Impact
deepmerge through 4.3.1 contains a prototype poisoning flaw in its mergeObject() routine. The merge function does not properly validate the keys that it writes to the target object, allowing attackers to supply malicious source objects that inject keys into the prototype chain. This causes all objects that inherit from the poisoned prototype to see unexpected values when accessing properties without own‑property checks, which can compromise confidentiality, integrity, or availability of the application depending on how those properties are used.
Affected Systems
The vulnerability affects the JavaScript library deepmerge developed by TehShrike. Versions up to 4.3.1 are impacted; any release that incorporates the documented mergeObject() logic without the change in the referenced commit is potentially vulnerable. No other vendors or products are known to be affected.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity impact if exploited. The EPSS score is below 1%, suggesting that zero‑day exploitation is currently rare, but might surface if the flaw is discovered and exploited in the wild. The vulnerability is not listed in the CISA KEV catalog, and the attack vector requires an attacker to supply malicious input to a mergeObject() call – typically through user data such as JSON payloads, query parameters, or configuration files. Successful exploitation would require the merge operation to be performed on untrusted data without additional validation, allowing prototype manipulation and potential downstream logic bypass.
OpenCVE Enrichment