lodash.zipobjectdeep@4.4.0 vulnerabilities

The lodash method `_.zipObjectDeep` exported as a module.

Direct Vulnerabilities

Known vulnerabilities in the lodash.zipobjectdeep package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Prototype Pollution

lodash.zipobjectdeep is a The lodash method _.zipObjectDeep exported as a module.

Affected versions of this package are vulnerable to Prototype Pollution through the zipObjectDeep function due to improper user input sanitization in the baseZipObject function.

Note

lodash.setwith is not maintained for a long time. It is recommended to use lodash library, which contains the fix since version 4.17.17.

How to fix Prototype Pollution?

There is no fixed version for lodash.zipobjectdeep.

*