HIGH 7.3 NVD
CVE-2026-54737
@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges
@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursively merges user-supplied objects without filtering proto, constructor, and prototype, allowing properties to be written to Object.prototype. This issue is fixed in version 2.0.5.
References
- https://github.com/phun-ky/defaults-deep/commit/807dba930f8718f9126cad59d949b8fd3539b059
- https://github.com/phun-ky/defaults-deep/pull/49
- https://github.com/phun-ky/defaults-deep/releases/tag/2.0.5
- https://github.com/phun-ky/defaults-deep/security/advisories/GHSA-mj3g-7xcc-x4vh
This high severity vulnerability with a CVSS score of 7.3 was published on 2026-07-31 via NVD.
vulnfeed aggregates 9166 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.