High severity7.5NVD Advisory· Published Aug 9, 2022· Updated Jun 17, 2026
CVE-2022-25907
CVE-2022-25907
Description
The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
ts-deepmergenpm | < 2.0.2 | 2.0.2 |
Affected products
3- cpe:2.3:a:typescript_deep_merge_project:typescript_deep_merge:*:*:*:*:*:node.js:*:*Range: <2.0.2
- ts-deepmerge/ts-deepmergedescription
Patches
Vulnerability mechanics
References
5- github.com/voodoocreation/ts-deepmerge/commit/9be5148773343c57be9de39728d6ead18eddf10bnvdPatchThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-TSDEEPMERGE-2959975nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-7qqq-gh2f-wq76ghsaADVISORY
- github.com/voodoocreation/ts-deepmerge/releases/tag/2.0.2nvdRelease NotesThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-25907ghsaADVISORY
News mentions
0No linked articles in our index yet.