Skip to content

fix(deepmerge): patch prototype pollution CVE-2026-93753 - #3438

Draft
dreamwasp wants to merge 1 commit into
mainfrom
cass-gmt-deepmerge-fix
Draft

dreamwasp wants to merge 1 commit into
mainfrom
cass-gmt-deepmerge-fix

Conversation

@dreamwasp

@dreamwasp dreamwasp commented Sep 23, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • deepmerge@4.3.1 (transitive via react-player, used in the Video component) has a prototype pollution vuln (CVE-2026-93753, CVSS 8.7, SNYK-JS-DEEPMERGE-19964053) with no upstream fix.
  • Patches deepmerge's mergeObject to reject __proto__/constructor/prototype keys in its unsafe-key check (.yarn/patches/deepmerge-npm-4.3.1-4f751a0844.patch), applied via yarn patch.
  • Pins all in-tree deepmerge semver ranges (^4.0.0, ^4.2.2, ^4.3.1) to the patched build via resolutions in package.json.

We also explored upgrading react-player to v3, which drops deepmerge entirely — see #3439. That's parked for now: it hard-breaks Codecademy's build (webpack 4 can't resolve v3's dependency chain, which relies on package.json exports maps with no fallback), so this patch is the safer near-term fix.

Test plan

  • Verified the patch blocks pollution directly (deepmerge({}, JSON.parse('{"__proto__":{"polluted":"yes"}}')) no longer sets Object.prototype.polluted)
  • yarn jest packages/gamut — 110 suites / 1459 tests pass
  • Confirm Snyk no longer flags SNYK-JS-DEEPMERGE-19964053 on next scan

🤖 Generated with Claude Code

@nx-cloud

nx-cloud Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

View your CI Pipeline Execution ↗ for commit 990e970


☁️ Nx Cloud last updated this comment at 2026-09-23 19:39:17 UTC

@dreamwasp dreamwasp changed the title fix(deepmerge): patch prototype pollution CVE-2026-93753 fix(Video): upgrade react-player to v3 to remove vulnerable deepmerge dependency Sep 23, 2026
@codecov

codecov Bot commented Sep 23, 2026 •

Copy link
Copy Markdown

⚠️ JUnit XML file not found

The CLI was unable to find any JUnit XML files to upload.
For more help, visit our troubleshooting guide.

deepmerge@4.3.1 (transitive via react-player, used in the Video
component) has no upstream fix for a prototype pollution vuln. Patch
mergeObject's unsafe-key check to reject __proto__/constructor/prototype
keys, and pin all in-tree deepmerge ranges to the patched build via
yarn resolutions.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@dreamwasp
dreamwasp force-pushed the cass-gmt-deepmerge-fix branch from 3c31d4d to 990e970 Compare September 23, 2026 19:36
@dreamwasp dreamwasp changed the title fix(Video): upgrade react-player to v3 to remove vulnerable deepmerge dependency fix(deepmerge): patch prototype pollution CVE-2026-93753 Sep 23, 2026
@codecademydev

Copy link
Copy Markdown
Collaborator

📬 Published Alpha Packages:

Package Version npm Diff
@codecademy/gamut 73.6.2-alpha.9c3965.0 npm diff
@codecademy/gamut-icons 10.2.1-alpha.9c3965.0 npm diff
@codecademy/gamut-illustrations 1.1.1-alpha.9c3965.0 npm diff
@codecademy/gamut-kit 3.0.25-alpha.9c3965.0 npm diff
@codecademy/gamut-patterns 1.1.1-alpha.9c3965.0 npm diff
@codecademy/gamut-styles 21.2.1-alpha.9c3965.0 npm diff
@codecademy/gamut-tests 7.1.1-alpha.9c3965.0 npm diff
@codecademy/variance 1.1.1-alpha.9c3965.0 npm diff
eslint-plugin-gamut 3.1.1-alpha.9c3965.0 npm diff

@github-actions

Copy link
Copy Markdown
Contributor

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants