Description
All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function.
Remediation
References
https://github.com/jesusgm/deepmergefn/blob/master/index.js%23L6
https://snyk.io/vuln/SNYK-JS-DEEPMERGEFN-1310984
Related Vulnerabilities
CVE-2020-7683 Vulnerability in npm package rollup-plugin-server
CVE-2023-26121 Vulnerability in npm package safe-eval
CVE-2023-26110 Vulnerability in npm package node-bluetooth
CVE-2019-14862 Vulnerability in npm package knockout
CVE-2020-9497 Vulnerability in maven package org.apache.guacamole:guacamole