Skip to content

[GHSA-653v-rqx9-j85p] deep-object-diff vulnerable to Prototype Pollution#7272

Open
rsholokh wants to merge 1 commit intorsholokh/advisory-improvement-7272from
rsholokh-GHSA-653v-rqx9-j85p
Open

[GHSA-653v-rqx9-j85p] deep-object-diff vulnerable to Prototype Pollution#7272
rsholokh wants to merge 1 commit intorsholokh/advisory-improvement-7272from
rsholokh-GHSA-653v-rqx9-j85p

Conversation

@rsholokh
Copy link
Copy Markdown

Updates

  • Affected products

Comments
If the safe version is 1.1.9, then the correct “Affected version” should be “< 1.1.9”. See SNYK report https://security.snyk.io/vuln/SNYK-JS-DEEPOBJECTDIFF-3104594

@github-actions github-actions bot changed the base branch from main to rsholokh/advisory-improvement-7272 March 31, 2026 15:56
@JonathanLEvans
Copy link
Copy Markdown

Hi @rsholokh,

We include the 1.1.6 lower bound based on this comment from the maintainer and #819.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants