CyberRota Analysis
AI-GeneratedThe vulnerability in deepmerge versions up to 4.3.1 allows attackers to exploit the mergeObject() function by injecting malicious properties into the prototype of target objects, leading to unintended inheritance of values in applications. This can result in unauthorized access or manipulation of application data, making it critical for developers using deepmerge to prioritize patching or upgrading to mitigate potential exploitation. Organizations that rely on this library for object merging in their applications should take immediate action to address this high-severity issue.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.