Description
merge is vulnerable to Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Remediation
References
https://github.com/viking04/merge/commit/baba40332080b38b33840d2614df6d4142dedaf6
https://huntr.dev/bounties/ef387a9e-ca3c-4c21-80e3-d34a6a896262
Related Vulnerabilities
CVE-2021-29060 Vulnerability in npm package color-string
CVE-2023-29199 Vulnerability in npm package vm2
CVE-2023-0674 Vulnerability in maven package com.xuxueli:xxl-job-core
CVE-2023-48711 Vulnerability in npm package google-translate-api-browser
CVE-2014-0035 Vulnerability in maven package org.apache.cxf:cxf-bundle-minimal