Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-93753

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Sep 18, 2026
Vendor unknown

Description

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.

References