Merge Deep Project
merge-deep_project
2 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (2)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Merge Deep Project Netapp2E Series Performance Analyzer Merge DeepJun 17, 2026 Jun 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The merge-deep library before 3.0.3 for Node.js can be tricked into overwriting properties of Object.prototype or adding new properties to it. These properties are then inherited by every object in the program, thus faci...Show more |
merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or mod...Show more |