THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-mj3g-7xcc-x4vh (high) — @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging

[GHSA] GHSA-mj3g-7xcc-x4vh (high) — @phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging

medgithub_advisoriesPublished 2026-07-31

GHSA-mj3g-7xcc-x4vh Severity: high CVE: CVE-2026-54737

@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging

### Impact

A prototype pollution vulnerability exists in @phun-ky/defaults-deep prior to version 2.0.5.

The library recursively merged user-supplied objects without filtering unsafe property names such as `__proto__`, `constructor`, and `prototype`

Indicators of compromise

Original source: https://github.com/advisories/GHSA-mj3g-7xcc-x4vh