Descripción
The Preset configuration
https://v2.vuetifyjs.com/en/features/presets feature of Vuetify is vulnerable to Prototype Pollution https://cheatsheetseries.owasp.org/cheatsheets/Prototype_Pollution_Prevention_Cheat_Sheet.html due the internal 'mergeDeep' utility function used merge options with defaults. Using a specially-crafted, malicious preset can result in polluting all JavaScript objects arbitrary properties, which further negatively affect aspects application's behavior. This lead wide range security issues, including resource exhaustion/denial service or unauthorized access data.
If application utilizes Server-Side Rendering (SSR), this vulnerability could whole server process.
This issue affects versions greater than equal 2.2.0-beta.2 and less 3.0.0-alpha.10.
Note:
Version 2.x End-of-Life and will not receive any updates address issue. For more information see here https://v2.vuetifyjs.com/en/about/eol/ .
https://codepen.io/herodevs/pen/RNWoaQM/f1f4ccc7e6a307c2a8c36d948ba14755
https://www.herodevs.com/vulnerability-directory/cve-2025-8083