High severity7.5NVD Advisory· Published Sep 18, 2026
CVE-2026-93753
CVE-2026-93753
Description
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.