High severityNVD Advisory· Published Jul 31, 2026· Updated Jul 31, 2026
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
CVE-2026-54737
Description
@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, allowing properties to be written to Object.prototype. This issue is fixed in version 2.0.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@phun-ky/defaults-deepnpm | < 2.0.5 | 2.0.5 |
Affected products
1- Range: <2.0.5
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-mj3g-7xcc-x4vhghsaADVISORY
- github.com/phun-ky/defaults-deep/commit/807dba930f8718f9126cad59d949b8fd3539b059ghsax_refsource_MISCWEB
- github.com/phun-ky/defaults-deep/pull/49ghsax_refsource_MISCWEB
- github.com/phun-ky/defaults-deep/releases/tag/2.0.5ghsax_refsource_MISCWEB
- github.com/phun-ky/defaults-deep/security/advisories/GHSA-mj3g-7xcc-x4vhghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.