HIGH
RebeccaStevens
CVE published 2026-08-20
CVE-2026-40345
The deepmerge-ts library, a TypeScript library for deep merging JavaScript objects, has a vulnerability in versions prior to 8.0.0. This vulnerability affects applications that merge recursive object graphs, particularly those with potential attacker-controlled input. The issue arises from the deepmerge, deepmergeCustom, deepmergeInto, and deepmergeIntoCustom APIs not tracking visited objects or object pa [truncated]