CVE-2026-93753 - High Severity Vulnerability
Vulnerable Library - deepmerge-2.2.1.tgz
A library for deep (recursive) merging of Javascript objects
Library home page: https://registry.npmjs.org/deepmerge/-/deepmerge-2.2.1.tgz
Sample Path to Dependency File: /ui/package.json
Path to vulnerable library: /ui/node_modules/.pnpm/deepmerge@2.2.1/node_modules/deepmerge/package.json
Dependency Hierarchy:
- @postgres.ai/ce-4.0.3.tgz (Root Library)
- formik-2.4.9.tgz
- ❌ deepmerge-2.2.1.tgz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.
Publish Date: 2026-09-18
URL: CVE-2026-93753
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Step up your Open Source Security Game with Mend here
CVE-2026-93753 - High Severity Vulnerability
A library for deep (recursive) merging of Javascript objects
Library home page: https://registry.npmjs.org/deepmerge/-/deepmerge-2.2.1.tgz
Sample Path to Dependency File: /ui/package.json
Path to vulnerable library: /ui/node_modules/.pnpm/deepmerge@2.2.1/node_modules/deepmerge/package.json
Dependency Hierarchy:
Found in base branch: master
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.
Publish Date: 2026-09-18
URL: CVE-2026-93753
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: High
- Availability Impact: None
For more information on CVSS3 Scores, click here.Step up your Open Source Security Game with Mend here