Versions of lodash before 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep allows a malicious user to modify the prototype of Object via {constructor: {prototype: {...}}} causing the addition or modification of an existing property that will exist on all objects.
Update to version 4.17.12 or later.
4.17.124.17.124.17.134.17.144.6.1Exploitability
AV:NAC:LPR:NUI:NScope
S:UImpact
C:NI:HA:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H