{"id":"GHSA-mhwj-73qx-jqxm","aliases":[],"url":"https://o3.security/vulnerability/GHSA-mhwj-73qx-jqxm","summary":"@theecryptochad/merge-guard has Prototype Pollution in its deepMerge() function","details":"## Summary\n\n`@theecryptochad/merge-guard` versions prior to 1.0.1 are vulnerable to Prototype Pollution via the `deepMerge()` function. An attacker who controls the source object can inject `__proto__` keys that mutate `Object.prototype`, affecting all objects in the Node.js runtime.\n\n## Details\n\nThe `deepMerge()` function recursively merges two objects without sanitizing reserved property keys (`__proto__`, `constructor`, `prototype`). When a source object contains a `__proto__` key, its value is assigned to `target.__proto__`, which JavaScript engines interpret as a write to `Object.prototype`.\n\n## Proof of Concept\n\n```js\nconst { deepMerge } = require('@theecryptochad/merge-guard');\nconst payload = JSON.parse('{\"__proto__\":{\"isAdmin\":true}}');\ndeepMerge({}, payload);\nconsole.log({}.isAdmin); // true — Object.prototype is polluted\n```\n\n## Impact\n\nAny application using `deepMerge()` with untrusted input (e.g. user-supplied JSON from HTTP requests, WebSocket messages, or config files) is vulnerable. An attacker can inject arbitrary properties onto `Object.prototype`, enabling privilege escalation, application logic bypass, and property injection.\n\n## Remediation\n\nUpgrade to `@theecryptochad/merge-guard >= 1.0.1`, which adds an explicit blocklist:\n\n```js\nconst BLOCKED = new Set(['__proto__', 'constructor', 'prototype']);\nif (BLOCKED.has(key)) continue;\n```\n\n## References\n- [CWE-1321: Improper Neutralization of Special Elements in Object Keys](https://cwe.mitre.org/data/definitions/1321.html)\n- [OWASP: Prototype Pollution](https://owasp.org/www-community/attacks/Prototype_Pollution)\n- [Fix commit](https://github.com/TheeCryptoChad/merge-guard/releases/tag/v1.0.1)","published":"2026-05-11T16:10:12Z","modified":"2026-05-11T16:17:52.734108Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@theecryptochad/merge-guard","fixedVersion":"1.0.1"}],"fix":{"url":"https://github.com/TheeCryptoChad/merge-guard/commit/25e4b4f2618578a656ef3cb4946a1b475f736736","label":"TheeCryptoChad/merge-guard@25e4b4f"},"references":[{"type":"WEB","url":"https://github.com/TheeCryptoChad/merge-guard/security/advisories/GHSA-mhwj-73qx-jqxm"},{"type":"WEB","url":"https://github.com/TheeCryptoChad/merge-guard/commit/25e4b4f2618578a656ef3cb4946a1b475f736736"},{"type":"PACKAGE","url":"https://github.com/TheeCryptoChad/merge-guard"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-05-11T16:17:52.734108Z"}}