Description
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Prototype pollution that can inject attacker-controlled properties into object prototypes, potentially altering application behavior
Action: Patch
AI Analysis

Impact

deepmerge through 4.3.1 contains a prototype poisoning flaw in its mergeObject() routine. The merge function does not properly validate the keys that it writes to the target object, allowing attackers to supply malicious source objects that inject keys into the prototype chain. This causes all objects that inherit from the poisoned prototype to see unexpected values when accessing properties without own‑property checks, which can compromise confidentiality, integrity, or availability of the application depending on how those properties are used.

Affected Systems

The vulnerability affects the JavaScript library deepmerge developed by TehShrike. Versions up to 4.3.1 are impacted; any release that incorporates the documented mergeObject() logic without the change in the referenced commit is potentially vulnerable. No other vendors or products are known to be affected.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity impact if exploited. The EPSS score is below 1%, suggesting that zero‑day exploitation is currently rare, but might surface if the flaw is discovered and exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, and the attack vector requires an attacker to supply malicious input to a mergeObject() call – typically through user data such as JSON payloads, query parameters, or configuration files. Successful exploitation would require the merge operation to be performed on untrusted data without additional validation, allowing prototype manipulation and potential downstream logic bypass.

Generated by OpenCVE AI on September 19, 2026 at 16:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade deepmerge to a fixed release if one is available; otherwise, ensure that the library is upgraded to the latest stable version that removes the prototype poisoning flaw.
  • Before calling mergeObject(), sanitize the source objects by whitelisting allowed property keys or removing any keys that could affect the prototype chain; alternatively, merge only trusted, internal data.
  • Implement defensive checks around any object that uses properties from the prototype chain, ensuring that own‑property checks (.hasOwnProperty or Object.prototype.hasOwnProperty.call) are performed before relying on property values.

Generated by OpenCVE AI on September 19, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Tehshrike
Tehshrike deepmerge
Vendors & Products Tehshrike
Tehshrike deepmerge

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.
Title deepmerge through 4.3.1 Prototype Poisoning via mergeObject
Weaknesses CWE-1321
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Tehshrike Deepmerge
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:12.090Z

Reserved: 2026-09-18T16:30:18.853Z

Link: CVE-2026-93753

cve-icon Vulnrichment

Updated: 2026-09-18T19:16:33.101Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T18:18:34.487

Modified: 2026-09-23T17:17:50.017

Link: CVE-2026-93753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:04:06Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')