Vendor
The @phun-ky/defaults-deep library is vulnerable to prototype pollution (CVE-2026-54737) via improper handling of recursive property merging, potentially allowing attackers to modify Object.prototype.