{"id":"CVE-2018-3722","aliases":["GHSA-9g9w-hmvj-5h57"],"url":"https://o3.security/vulnerability/CVE-2018-3722","summary":"Prototype Pollution in merge-deep","details":"merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of \"Object\" via __proto__, causing the addition or modification of an existing property that will exist on all objects.","published":"2018-06-07T02:29:08.363Z","modified":"2026-07-08T20:14:47.767965Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"merge-deep","fixedVersion":"3.0.1"}],"fix":{"url":"https://github.com/jonschlinkert/merge-deep/commit/2c33634da7129a5aefcc262d2fec2e72224404e5","label":"jonschlinkert/merge-deep@2c33634"},"references":[{"type":"FIX","url":"https://github.com/jonschlinkert/merge-deep/commit/2c33634da7129a5aefcc262d2fec2e72224404e5"},{"type":"EVIDENCE","url":"https://hackerone.com/reports/310708"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T20:14:47.767965Z"}}