VDB
Sign up
MEDIUM5.3

GHSA-87mf-gv2c-c62c

ts-deepmerge: Prototype Method Override leads to DoS

Quick fix

GHSA-87mf-gv2c-c62c — ts-deepmerge: upgrade to the fixed version with the command below.

npm install ts-deepmerge@8.0.0

Details

Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf). When user-controlled input contains these keys with non-function values, the resulting merged object becomes broken — any string context operation throws a TypeError, crashing the application.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/ts-deepmerge
Introduced in: 0Fixed in: 8.0.0
Fixnpm install ts-deepmerge@8.0.0

References