Hi,
I would like to report a vulnerability which I found in your npm package nested-object-assign (v1.0.4)
In accordance with responsible disclosure practices, I would be happy to report it via a GitHub security advisory (https://github.com/Geta/NestedObjectAssign/security/advisories/new) and coordinate with you on a fix.
Best regards,
Kevin