All versions of package @ianwalter/merge are vulnerable to Prototype Pollution via the main (merge) function. @ianwalter/merge is deprecated and the maintainer suggests using @generates/merger instead.
{
"github_reviewed_at": "2022-07-26T19:37:36Z",
"github_reviewed": true,
"severity": "MODERATE",
"nvd_published_at": "2022-07-25T14:15:00Z",
"cwe_ids": [
"CWE-1321"
]
}