deepmerge-ts is used to merge 2 or more objects respecting type information. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). A fix was released in version 4.0.2. Currently, there is no known workaround.
{
"github_reviewed_at": "2022-04-01T17:26:03Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-1321",
"CWE-915"
],
"nvd_published_at": "2022-04-01T00:15:00Z",
"severity": "HIGH"
}