CVE-2026-93753: Tehshrike Deepmerge
High severity, CVSS 7.5. EPSS: 0.5% chance of exploitation in the next 30 days.
deepmerge through 4.3.1 contains a prototype poisoning vulnerability in the mergeObject() function that fails to properly validate keys being written to target objects. Attackers can supply malicious source objects in merge operations to inject attacker-controlled properties into the returned object's prototype, causing applications to inherit unintended values when accessing properties without own-property checks.
Affected products
- Tehshrike Deepmerge: up to and including 4.3.1
Published 2026-09-18. Last modified 2026-09-23.