Versions of default-deep before 0.2.4 are vulnerable to prototype pollution Recommendation Update to version 0.2.4 or later. References https://nvd.nist.gov/vuln/detail/CVE-2018-3723 https://hackerone.com/reports/310514 https://github.com/advisories/GHSA-cqp5-m4pq-gfgp https://www.npmjs.com/advisories/581 https://github.com/jonschlinkert/defaults-deep/commit/c873f341327ad885ff4d0f23b3d3bca31b0343e5