Versions of deep-extend before 0.5.1 are vulnerable to prototype pollution.
deep-extend
Update to version 0.5.1 or later.
{ "affected_functions": [ "(deep-extend)" ] }