Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-93753— deepmerge through 4.3.1 Prototype Poisoning via mergeObject

Quick assessment

Affected
TehShrike deepmerge
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

deepmerge 4.3.1 及更早版本在 函数中存在原型污染漏洞。该函数在将键写入目标对象时未进行充分验证。攻击者可以通过在合并操作中输入恶意的源对象,向返回对象的 (原型)中注入由攻击者控制的属性,从而导致应用程序在访问属性时(若未执行自有属性检查),意外地继承这些非预期的值。

CVSS 7.5 · High

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application

Affected Version Matrix 1

VendorProduct Version RangeStatus
TehShrike deepmerge ≤ 4.3.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-93753

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
deepmerge through 4.3.1 Prototype Poisoning via mergeObject
Source: CVE Program / CVE List V5
Vulnerability Description
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
CWE-1321
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
TehShrike deepmerge 0 ~ 4.3.1 -

II. Public POCs for CVE-2026-93753

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-93753

登录查看更多情报信息。

Other References for CVE-2026-93753 (3)

IV. Related Vulnerabilities

V. Comments for CVE-2026-93753

No comments yet


Leave a comment