{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3adeepmerge_projectdeepmergenode.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:deepmerge_project:deepmerge:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-93753"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["deepmerge (\u003c= 4.3.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe popular deepmerge JavaScript library, specifically versions 4.3.1 and below, contains a prototype pollution vulnerability within its mergeObject() function. The flaw stems from insufficient validation of keys being processed during object merge operations. When an application utilizes this library to merge user-supplied input into an existing object, an attacker can craft a malicious source object containing sensitive keys, such as \u003cstrong\u003eproto\u003c/strong\u003e or constructor, to overwrite prototype properties. This allows an attacker to inject arbitrary values that will then be inherited by other objects within the application's runtime. If the downstream application performs property access without explicit own-property checks, these injected values can influence logic, potentially leading to denial of service, security bypasses, or remote code execution depending on how the application uses the tainted properties.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to pollute the global object prototype, which may alter the behavior of an application in unintended ways. Potential consequences include bypassing authentication checks, modifying application logic, or causing application crashes. Given the library's widespread use in Node.js and browser-based JavaScript environments, the scope of affected software is significant.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of any application using deepmerge version 4.3.1 or earlier.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the deepmerge package to a version that addresses CVE-2026-93753.\u003c/li\u003e\n\u003cli\u003eReview codebases for the use of deepmerge where user-supplied input is passed directly to the merge function without prior sanitization or schema validation.\u003c/li\u003e\n\u003cli\u003eImplement recursive object freezing or use Object.create(null) for target objects where applicable to mitigate the risk of prototype pollution.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T20:07:30Z","date_published":"2026-09-18T20:07:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-deepmerge-prototype-poisoning/","summary":"The deepmerge library up to version 4.3.1 contains a prototype pollution vulnerability in the mergeObject() function, allowing attackers to inject malicious properties into objects.","title":"Prototype Pollution Vulnerability in deepmerge","url":"https://feed.craftedsignal.io/briefs/2026-09-deepmerge-prototype-poisoning/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:deepmerge_project:deepmerge:*:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}