Description
All versions of package deepmergefn are vulnerable to Prototype Pollution via deepMerge function.
Remediation
References
https://github.com/jesusgm/deepmergefn/blob/master/index.js%23L6
https://snyk.io/vuln/SNYK-JS-DEEPMERGEFN-1310984
Related Vulnerabilities
CVE-2023-29514 Vulnerability in maven package org.xwiki.platform:xwiki-platform-administration-ui
CVE-2022-41828 Vulnerability in maven package com.amazon.redshift:redshift-jdbc42
CVE-2022-24375 Vulnerability in npm package node-opcua
CVE-2019-15138 Vulnerability in maven package org.webjars.npm:html-pdf
CVE-2023-31544 Vulnerability in maven package org.opencms:opencms-core