Executive brief
merge-deep is a Node.js library used to recursively merge JavaScript objects. A prototype pollution vulnerability allows attackers to inject malicious properties into the Object.prototype, affecting all objects in an application and potentially enabling remote code execution, data manipulation, or denial of service depending on how the affected application uses merged data.
Technical details
merge-deep before version 3.0.3 is vulnerable to prototype pollution (CWE-1321), a vulnerability in which an attacker can inject arbitrary properties into Object.prototype by crafting a malicious object and passing it to the merge function. The library fails to properly validate or filter key names during the recursive merge process, allowing keys like "__proto__" or "constructor.prototype" to be processed. This vulnerability is network-accessible if the merged data originates from untrusted sources (e.g., API requests, user input), requiring no authentication or user interaction. An attacker can poison the prototype chain to inject properties inherited by all objects, leading to authentication bypasses, logic corruption, or arbitrary code execution in the affected application. The fix (version 3.0.3) adds key validation via an isValidKey function.
Affected products
- npm merge-deep before 3.0.3
Timeline
- 2021-06-07: disclosed: Vulnerability disclosed via GitHub Advisory
- 2021-06-03: patched: Fix committed to address prototype pollution with isValidKey function