PT-2026-95593 · Npm · Merge-Deep

·

CVE-2026-93753

·

Published

2026-09-18

·

Updated

2026-09-22

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions deepmerge versions prior to 4.3.2
Description The mergeObject() function fails to properly validate keys written to target objects, leading to prototype poisoning. This occurs when a crafted source object containing keys such as proto, constructor, or prototype is used in merge operations, allowing an attacker to inject controlled properties into the returned object's prototype. Consequently, applications may inherit unintended values when accessing properties without performing own-property checks. This issue does not impact merges involving fully trusted objects.
Recommendations Update deepmerge to version 4.3.2 or later.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93753

Affected Products

Merge-Deep