All versions of merge-objects are vulnerable to Prototype Pollution.
Recommendation
No fix is available for this vulnerability at this time. It is our recommendation to use an alternative package.
References:An open API service providing security vulnerability metadata for many open source software ecosystems.
| Affected Packages | Affected Versions | Fixed Versions | |
|---|---|---|---|
|
npm:merge-objects
PURL:
pkg:npm/merge-objects
|
>= 0.0.0 | No known fixed version | |
Affected Version RangesAll affected versions1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5 |
|||
All versions of merge-objects are vulnerable to Prototype Pollution.
No fix is available for this vulnerability at this time. It is our recommendation to use an alternative package.
References: