GHSA-737v-mqg7-c878
defu: Prototype pollution via `__proto__` key in defaults argument
Quick fix
GHSA-737v-mqg7-c878 — defu: upgrade to the fixed version with the command below.
npm install defu@6.1.5Details
### Impact
Applications that pass unsanitized user input (e.g. parsed JSON request bodies, database records, or config files from untrusted sources) as the first argument to `defu()` are vulnerable to prototype pollution.
A crafted payload containing a `__proto__` key can override intended default values in the merged result:
```js import { defu } from 'defu'
const userInput = JSON.parse('{"__proto__":{"isAdmin":true}}') const config = defu(userInput, { isAdmin: false })
config.isAdmin // true — attacker overrides the server default ```
### Root Cause
The internal `_defu` function used `Object.assign({}, defaults)` to copy the defaults object. `Object.assign` invokes the `__proto__` setter, which replaces the resulting object's `[[Prototype]]` with attacker-controlled values. Properties inherited from the polluted prototype then bypass the existing `__proto__` key guard in the `for...in` loop and land in the final result.
### Fix
Replace `Object.assign({}, defaults)` with object spread (`{ ...defaults }`), which uses `[[DefineOwnProperty]]` and does not invoke the `__proto__` setter.
### Affected Versions
<= 6.1.4
### Credits
Reported by [@BlackHatExploitation](https://github.com/BlackHatExploitation)
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/unjs/defu/security/advisories/GHSA-737v-mqg7-c878[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-35209[ADVISORY]
- https://github.com/unjs/defu/pull/156[WEB]
- https://github.com/unjs/defu/commit/3942bfbbcaa72084bd4284846c83bd61ed7c8b29[WEB]
- https://github.com/unjs/defu[PACKAGE]
- https://github.com/unjs/defu/releases/tag/v6.1.5[WEB]