High severity8.1NVD Advisory· Published Apr 1, 2022· Updated Jun 17, 2026
CVE-2022-24802
CVE-2022-24802
Description
deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. deepmerge-ts is vulnerable to Prototype Pollution via file deepmerge.ts, function defaultMergeRecords(). This issue has been patched in version 4.0.2. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
deepmerge-tsnpm | < 4.0.2 | 4.0.2 |
Affected products
2- RebeccaStevens/deepmerge-tsv5Range: < 4.0.2
Patches
Vulnerability mechanics
References
5- github.com/RebeccaStevens/deepmerge-ts/commit/b39f1a93d9e1c3541bd2fe159fd696a16dbe1c72nvdPatchThird Party AdvisoryWEB
- github.com/RebeccaStevens/deepmerge-ts/commit/d637db7e4fb2bfb113cb4bc1c85a125936d7081bnvdPatchThird Party AdvisoryWEB
- github.com/RebeccaStevens/deepmerge-ts/security/advisories/GHSA-r9w3-g83q-m6hqnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-r9w3-g83q-m6hqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-24802ghsaADVISORY
News mentions
0No linked articles in our index yet.