Description
deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-DEEPLY-451026
Related Vulnerabilities
CVE-2021-28860 Vulnerability in npm package mixme
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http
CVE-2023-24057 Vulnerability in maven package ca.uhn.hapi.fhir:org.hl7.fhir.utilities
CVE-2020-6537 Vulnerability in maven package org.webjars.npm:electron
CVE-2020-5529 Vulnerability in maven package net.sourceforge.htmlunit:htmlunit