deeply@2.0.3 vulnerabilities

A toolkit for deep structure manipulations, provides deep merge/clone functionality out of the box, and exposes hooks and custom adapters for more control and greater flexibility.

Direct Vulnerabilities

Known vulnerabilities in the deeply package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Prototype Pollution

deeply is an a toolkit for deep structure manipulations, provides deep merge/clone functionality out of the box, and exposes hooks and custom adapters for more control and greater flexibility.

Affected versions of this package are vulnerable to Prototype Pollution. The function assign-deep could be tricked into adding or modifying properties of Object.prototype using a _proto_ payload.

How to fix Prototype Pollution?

Upgrade deeply to version 3.1.0 or higher.

<3.1.0