MEDIUMnpm

@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging

@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging

CVE-2026-54737Published 5 days agoUpdated 5 days agoSource: OSV

Affected packages

  • @phun-ky/defaults-deep

Exploit signal

Known exploited (CISA KEV)
No
EPSS score
0.26%
EPSS percentile
17.9%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 18%.

@phun-ky/defaults-deep Has a Prototype Pollution issue via Unsafe Recursive Property Merging | HackTribune