VDB
Sign up
HIGH7.5

GHSA-mhwj-73qx-jqxm

@theecryptochad/merge-guard has Prototype Pollution in its deepMerge() function

Quick fix

GHSA-mhwj-73qx-jqxm — @theecryptochad/merge-guard: upgrade to the fixed version with the command below.

npm install @theecryptochad/merge-guard@1.0.1

Details

## Summary

`@theecryptochad/merge-guard` versions prior to 1.0.1 are vulnerable to Prototype Pollution via the `deepMerge()` function. An attacker who controls the source object can inject `__proto__` keys that mutate `Object.prototype`, affecting all objects in the Node.js runtime.

## Details

The `deepMerge()` function recursively merges two objects without sanitizing reserved property keys (`__proto__`, `constructor`, `prototype`). When a source object contains a `__proto__` key, its value is assigned to `target.__proto__`, which JavaScript engines interpret as a write to `Object.prototype`.

## Proof of Concept

```js const { deepMerge } = require('@theecryptochad/merge-guard'); const payload = JSON.parse('{"__proto__":{"isAdmin":true}}'); deepMerge({}, payload); console.log({}.isAdmin); // true — Object.prototype is polluted ```

## Impact

Any application using `deepMerge()` with untrusted input (e.g. user-supplied JSON from HTTP requests, WebSocket messages, or config files) is vulnerable. An attacker can inject arbitrary properties onto `Object.prototype`, enabling privilege escalation, application logic bypass, and property injection.

## Remediation

Upgrade to `@theecryptochad/merge-guard >= 1.0.1`, which adds an explicit blocklist:

```js const BLOCKED = new Set(['__proto__', 'constructor', 'prototype']); if (BLOCKED.has(key)) continue; ```

## References - [CWE-1321: Improper Neutralization of Special Elements in Object Keys](https://cwe.mitre.org/data/definitions/1321.html) - [OWASP: Prototype Pollution](https://owasp.org/www-community/attacks/Prototype_Pollution) - [Fix commit](https://github.com/TheeCryptoChad/merge-guard/releases/tag/v1.0.1)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@theecryptochad/merge-guard
Introduced in: 0Fixed in: 1.0.1
Fixnpm install @theecryptochad/merge-guard@1.0.1

References