{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/phun-ky/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-54737"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["defaults-deep"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["phun-ky"],"content_html":"\u003cp\u003eThe npm package @phun-ky/defaults-deep is affected by a prototype pollution vulnerability prior to version 2.0.5 (tracked as CVE-2026-54737). The library performs recursive object merging without verifying the presence of dangerous keys such as \u003cstrong\u003eproto\u003c/strong\u003e, constructor, and prototype. By passing specially crafted, untrusted objects to the defaultsDeep() function, an attacker can influence the behavior of all objects within the Node.js application process. This vulnerability is significant as it can lead to application logic bypasses, denial of service, or, in specific contexts, remote code execution. Defenders should identify applications utilizing this library and prioritize upgrading to version 2.0.5, which includes filters to block the injection of these reserved property names.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the modification of the base Object prototype, which affects all objects across the application's runtime environment. This can result in denial of service by corrupting system functionality, or enable logic bypasses that deviate from expected application code flow. Impact is dependent on the application's specific implementation of objects and how the polluted properties are subsequently accessed or utilized.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit dependencies to identify use of @phun-ky/defaults-deep versions earlier than 2.0.5.\u003c/li\u003e\n\u003cli\u003eUpgrade the dependency to version 2.0.5 or later to apply the built-in property filtering.\u003c/li\u003e\n\u003cli\u003eIf patching is not immediately feasible, implement input sanitization logic to strip '\u003cstrong\u003eproto\u003c/strong\u003e', 'constructor', and 'prototype' keys from any untrusted data objects before passing them to the merge function.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-07-31T19:29:20Z","date_published":"2026-07-31T19:29:20Z","id":"https://feed.craftedsignal.io/briefs/2026-07-phun-ky-prototype-pollution/","summary":"The @phun-ky/defaults-deep library is vulnerable to prototype pollution (CVE-2026-54737) via improper handling of recursive property merging, potentially allowing attackers to modify Object.prototype.","title":"Prototype Pollution in @phun-ky/defaults-deep","url":"https://feed.craftedsignal.io/briefs/2026-07-phun-ky-prototype-pollution/"}],"language":"en","title":"CraftedSignal Threat Feed - Phun-Ky","version":"https://jsonfeed.org/version/1.1"}