Prototype Pollution Vulnerability in Defaults-Deep Library by NPM
CVE-2018-16486
9.8CRITICAL
What is CVE-2018-16486?
A prototype pollution vulnerability exists in the Defaults-Deep library versions up to 0.2.4, where an attacker can exploit the functionality to manipulate properties on Object.prototype. This weakness can lead to severe security implications, allowing malicious users to inject unintended properties that can affect the integrity and behavior of applications utilizing this library.
Affected Version(s)
defaults-deep <=0.2.4