4.6.2
12 years ago
6 years ago
Known vulnerabilities in the lodash.merge package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for freeVulnerability | Vulnerable Version |
---|---|
lodash.merge is a Lodash method _.merge exported as a Node.js module. Affected versions of this package are vulnerable to Prototype Pollution. The functions How to fix Prototype Pollution? Upgrade | <4.6.2 |
lodash.merge is a Lodash method _.merge exported as a Node.js module. Affected versions of this package are vulnerable to Prototype Pollution. The utilities function allow modification of the How to fix Prototype Pollution? Upgrade | <4.6.2 |