CRITICAL9.8
GHSA-7qqq-gh2f-wq76
ts-deepmerge before 2.0.2 vulnerable to Prototype Pollution
Quick fix
GHSA-7qqq-gh2f-wq76 — ts-deepmerge: upgrade to the fixed version with the command below.
npm install ts-deepmerge@2.0.2Details
The package ts-deepmerge before version 2.0.2 is vulnerable to Prototype Pollution due to missing sanitization of the `merge` function.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25907[ADVISORY]
- https://github.com/voodoocreation/ts-deepmerge/commit/9be5148773343c57be9de39728d6ead18eddf10b[WEB]
- https://github.com/voodoocreation/ts-deepmerge[PACKAGE]
- https://github.com/voodoocreation/ts-deepmerge/releases/tag/2.0.2[WEB]
- https://security.snyk.io/vuln/SNYK-JS-TSDEEPMERGE-2959975[WEB]