Lucene search

K
osvGoogleOSV:GHSA-F9CM-QMX5-M98H
HistoryNov 01, 2018 - 2:45 p.m.

Prototype Pollution in merge

2018-11-0114:45:42
Google
osv.dev
9

0.001 Low

EPSS

Percentile

45.1%

Versions of merge before 1.2.1 are vulnerable to prototype pollution. The merge.recursive function can be tricked into adding or modifying properties of the Object prototype.

Recommendation

Update to version 1.2.1 or later.

CPENameOperatorVersion
mergelt1.2.1

0.001 Low

EPSS

Percentile

45.1%