THREAT OPS › Threat News › [GHSA] GHSA-mj3g-7xcc-x4vh (high) — @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
[GHSA] GHSA-mj3g-7xcc-x4vh (high) — @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
GHSA-mj3g-7xcc-x4vh Severity: high CVE: CVE-2026-54737
@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging
### Impact
A prototype pollution vulnerability exists in @phun-ky/defaults-deep prior to version 2.0.5.
The library recursively merged user-supplied objects without filtering unsafe property names such as `__proto__`, `constructor`, and `prototype`
Indicators of compromise
- CVE-2026-54737cve
Original source: https://github.com/advisories/GHSA-mj3g-7xcc-x4vh