Skip to content

[Snyk:Critical] Prototype pollution - due (04/22/2026) #7044

@pkfec

Description

@pkfec

Overview

Affected versions of this package are vulnerable to Prototype Pollution in the mergeDeep, mergeDeepWith, merge, Map.toJS, and Map.toObject functions. An attacker can inject arbitrary properties into object prototypes by supplying crafted input containing special keys, potentially leading to privilege escalation or bypassing security checks.

Introduced through

[email protected]

Fixed in

[email protected], @5.1.5

Action items

Completion criteria

  • snyk vulnerability is remediated

Metadata

Metadata

Assignees

Type

Projects

Status

📥 Assigned

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions