Skip to content

Commit 2d156c7

Browse files
authored
fix(merge): prevent possible prototype pollution (#34)
1 parent 56923fe commit 2d156c7

File tree

1 file changed

+1
-0
lines changed

1 file changed

+1
-0
lines changed

src/merge.js

+1
Original file line numberDiff line numberDiff line change
@@ -6,6 +6,7 @@ export function merge(a, b, k) {
66
}
77
} else {
88
for (k in b) {
9+
if (k === '__proto__' || k === 'constructor' || k === 'prototype') break;
910
a[k] = merge(a[k], b[k]);
1011
}
1112
}

0 commit comments

Comments
 (0)