Launch Week Day 1: Announcing Security Design Review
HIGH 8.2 npm

@ranfdev/deepobj has a Prototype Pollution vulnerability

GHSA-x7q7-fchv-8h2j · CVE-2026-46509

Published · Modified

Description

Impact

Prototype pollution is possible when property paths contain __proto__/constructor/prototype. The property path must not be exposed as user input.

Ready to move

Start Securing

Free, no credit card | First findings in minutes