GHSA-3jp5-5f8r-q2wg
HIGHCVE-2025-8083The Preset configuration feature of Vuetify is vulnerable to Prototype Pollution due to the internal 'mergeDeep' utility function used to merge options with defaults. Using a specially-crafted, malicious preset can result in polluting all JavaScript objects with arbitrary properties, which can further negatively affect all aspects of the application's behavior. This can lead to a wide range of sec
- Affected
- >= 2.2.0-beta.2, < 3.0.0-alpha.10
- Fixed in
- 3.0.0-alpha.10
- Weakness
- CWE-1321
- Published
- 2025-12-12
- Source
- github