deepmerge 4.3.1 及更早版本在 函数中存在原型污染漏洞。该函数在将键写入目标对象时未进行充分验证。攻击者可以通过在合并操作中输入恶意的源对象,向返回对象的 (原型)中注入由攻击者控制的属性,从而导致应用程序在访问属性时(若未执行自有属性检查),意外地继承这些非预期的值。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet