Description
deeply is vulnerable to Prototype Pollution in versions before 3.1.0. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using using a _proto_ payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-DEEPLY-451026
Related Vulnerabilities
CVE-2021-46440 Vulnerability in npm package strapi
CVE-2020-15270 Vulnerability in npm package parse-server
CVE-2020-7662 Vulnerability in npm package websocket-extensions
CVE-2019-13236 Vulnerability in maven package org.opencms:opencms-core
CVE-2022-35915 Vulnerability in npm package @openzeppelin/contracts-upgradeable