CVE-2024-38986: 75lb Deep-Merge

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

Prototype Pollution in 75lb deep-merge 1.1.1 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) and cause other impacts via merge methods of lodash to merge objects.

Affected products

  • 75lb Deep-Merge: version 1.1.1 only

Published 2024-07-30. Last modified 2026-06-17.