VDB
Sign up
CRITICAL9.8

GHSA-fhjf-83wg-r2j9

Prototype Pollution in mixin-deep

Quick fix

GHSA-fhjf-83wg-r2j9 — mixin-deep: upgrade to the fixed version with the command below.

npm install mixin-deep@1.3.2

Details

Versions of `mixin-deep` prior to 2.0.1 or 1.3.2 are vulnerable to Prototype Pollution. The `mixinDeep` function fails to validate which Object properties it updates. This allows attackers to modify the prototype of Object, causing the addition or modification of an existing property on all objects.

## Recommendation

If you are using `mixin-deep` 2.x, upgrade to version 2.0.1 or later. If you are using `mixin-deep` 1.x, upgrade to version 1.3.2 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mixin-deep
Introduced in: 0Fixed in: 1.3.2
Fixnpm install mixin-deep@1.3.2
npm/mixin-deep
Introduced in: 2.0.0Fixed in: 2.0.1
Fixnpm install mixin-deep@2.0.1

References