Executive brief
deepmerge-ts is a JavaScript library that merges multiple objects together while preserving type information. A prototype pollution vulnerability allows attackers to modify properties on JavaScript object prototypes, potentially affecting all objects in the application. This could lead to unexpected behavior, data manipulation, or execution of malicious code within applications using the library.
Technical details
deepmerge-ts is vulnerable to prototype pollution in the defaultMergeRecords() function within deepmerge.ts. The vulnerability occurs when the library merges objects without properly validating or sanitizing property names, allowing an attacker to inject properties like __proto__, constructor, or prototype into the merge process. This is a network-reachable attack that requires only untrusted input to the merge function; no authentication is required. An attacker can poison the object prototype chain, affecting all objects created thereafter in the application. The vulnerability was patched in version 4.0.2.
Affected products
- Rebecca Stevens deepmerge-ts all versions before 4.0.2
Timeline
- 2022-03-31: disclosed
- 2022-04-01: patched: Version 4.0.2 released