Immer version < 9.0.6 is vulnerable to Prototype Pollution https://snyk.io/vuln/SNYK-JS-IMMER-1540542 https://github.com/advisories/GHSA-9qmh-276g-x5pj Immer version 9.0.6 resolves the vulnerability: https://github.com/immerjs/immer/releases/tag/v9.0.6