HIGH
phun-ky
CVE published 2026-07-31
CVE-2026-54737
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T18:17:17.330Z and has not been modified since then. The @phun-ky/defaults-deep library, similar to lodash defaultsDeep, preserves arrays and does not depend on lodash. Versions before 2.0.5 are vulnerable, allowing properties to be written to Object.prototype due to a lack of filtering on proto, [truncated]