Versions of mixin-deep before 1.3.1 are vulnerable to prototype pollution via merging functions. External References: https://nodesecurity.io/advisories/578 https://hackerone.com/reports/311236
Created nodejs-mixin-deep tracking bugs for this issue: Affects: fedora-28 [bug 1576649]
This issue has been addressed in Rawhide with an upgrade to version 1.3.1, and an update has been proposed for F28: https://bodhi.fedoraproject.org/updates/FEDORA-2018-ab62814cee
ARRAY(0x55ab81ab9018)