Prototype Pollution
CVE-2022-25907
7.5HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 9 August 2022
What is CVE-2022-25907?
The package ts-deepmerge before 2.0.2 are vulnerable to Prototype Pollution due to missing sanitization of the merge function.
Affected Version(s)
ts-deepmerge < 2.0.2
