CVE-2026-93753: Tehshrike Deepmerge

High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.

deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.

Affected products

  • Tehshrike Deepmerge: up to and including 4.3.1

Published 2026-09-18. Last modified 2026-09-23.