Sploitus

CVE-2026-12644

No indexed exploits for CVE-2026-12644 yet

Versions of the package ts-deepmerge before 8.0.0 are vulnerable to Uncaught Exception due to the improper handling of built-in Object.prototype methods (such as toString, valueOf). When user-controlled input contains these keys with non-function values, the resulting merged object becomes broken β€” any string context operation throws a TypeError, crashing the application.

Affected products
Ts-Deepmerge
Fix
Available
CVSS 4.0
6.9 MEDIUM
CVSS 3.1
5.3 MEDIUM
EPSS
0.5% (41th percentile)
Weakness
CWE-248
NVD status
Deferred
Published
2026-06-19
CVE-2026-12644 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-12644 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-12644 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows β€” not that no exploit exists.