Description
assign-deep is vulnerable to Prototype Pollution in versions before 0.4.8 and version 1.0.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using either a constructor or a _proto_ payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-ASSIGNDEEP-450211
Related Vulnerabilities
CVE-2020-7631 Vulnerability in npm package diskusage-ng
CVE-2017-16084 Vulnerability in npm package list-n-stream
CVE-2023-40177 Vulnerability in maven package org.xwiki.platform:xwiki-platform-appwithinminutes-ui
CVE-2022-39300 Vulnerability in npm package node-saml
CVE-2020-19697 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md