VDB
Sign up
HIGH8.8

GHSA-xcvv-84j5-jw9h

Prototype Pollution in assign-deep

Quick fix

GHSA-xcvv-84j5-jw9h — assign-deep: upgrade to the fixed version with the command below.

npm install assign-deep@0.4.7

Details

Versions of `assign-deep` before 0.4.7 are vulnerable to prototype pollution via merging functions.

## Recommendation

Update to version 0.4.7 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/assign-deep
Introduced in: 0Fixed in: 0.4.7
Fixnpm install assign-deep@0.4.7

References