mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
{ "binaries": [ { "binary_name": "node-mixin-deep", "binary_version": "1.1.3-1" } ] }