{"id":"GHSA-fg4m-w35q-vfg2","summary":"@zag-js/core prototype pollution","details":"A prototype pollution in the lib.deepMerge function of @zag-js/core v0.50.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted payload.","aliases":["CVE-2024-57079"],"modified":"2025-03-19T15:40:29Z","published":"2025-02-06T06:31:26Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-02-06T23:32:24Z","nvd_published_at":"2025-02-05T22:15:32Z","cwe_ids":["CWE-1321","CWE-400"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-57079"},{"type":"WEB","url":"https://github.com/chakra-ui/zag/pull/2255"},{"type":"WEB","url":"https://github.com/chakra-ui/zag/commit/f53edc548f737aadfdd486a0043bdd5f5c068bbf"},{"type":"WEB","url":"https://gist.github.com/tariqhawis/4778fc57084766b7b7fb6d25d20b7b9b"},{"type":"PACKAGE","url":"https://github.com/chakra-ui/zag"}],"affected":[{"package":{"name":"@zag-js/core","ecosystem":"npm","purl":"pkg:npm/%40zag-js/core"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.82.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/02/GHSA-fg4m-w35q-vfg2/GHSA-fg4m-w35q-vfg2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}