smart-extend@1.4.1 vulnerabilities

Merge/extend objects (shallow/deep) with global/individual filters and more features

Direct Vulnerabilities

Known vulnerabilities in the smart-extend package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Prototype Pollution

smart-extend is an extension to jQuery's classic extend() method with additional features providing you with more power and control over your object extensions/clones. Works in both Node.JS and the browser.

Affected versions of this package are vulnerable to Prototype Pollution. deep function is vulnerable when it performs a recursive copy of the specified objects.

How to fix Prototype Pollution?

There is no fixed version for smart-extend.

*