CVE-2026-93753

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-22: 209-22
Referenced assets1 URL
By indicator
Full discourse2 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters

    CVE-2026-93753: prototype poisoning in deepmerge's mergeObject() lets attackers inject properties into object prototypes via crafted merge input. CVSS 7.5, still unpatched. Audit your merge calls and pin versions now. https://www.valtersit.com/cve/CVE-2026-93753 #CVE #infosec #javascript #deepmerge #CVEALERT #CVE #infosec #Linux #XSS #valtersit #snippet #SysAdmin #cybersecurity #devsecops #devops #developer #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #cybersecurityawareness #cybersecuritynews #cybersecuritytips #python #hacker #kali #ubuntu #debian #docker

    0000017
    1.1K followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨High - deepmerge Prototype Pollution via mergeObject() (CVE-2026-93753) deepmerge <= 4.3.1 fails to validate dangerous keys in mergeObject(), allowing a crafted source object with __proto__/constructor/prototype to poison the returned object's prototype during merge. Downstream code that reads properties without own-property checks can inherit attacker-controlled values; merges of fully trusted objects are not impacted. 👉Affected: deepmerge <= 4.3.1

    0000040
    304 followersView on X

Explore more