diff --git a/src/core.js b/src/core.js index ed1f18e..0556a11 100644 --- a/src/core.js +++ b/src/core.js @@ -42,14 +42,18 @@ function _deepObjectTraverse(target, path, create = true) { if (!_isObject(target[step])) { if (create) target[step] = {}; else return undefined; - } + } else if (isPrototypePolluted(step)) continue; target = target[step]; } return target; } +function isPrototypePolluted(key) { + return ['__proto__', 'constructor', 'prototype'].includes(key); +} + module.exports = { _deepObjectOperation, _isObject, _deepObjectTraverse -} \ No newline at end of file +}