merge-deep node module before 3.0.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious…
hackerone·CWE-471·Published 2018-06-07