Description
A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/390860
Related Vulnerabilities
CVE-2021-28162 Vulnerability in npm package @wiptheia/core
CVE-2022-28366 Vulnerability in maven package net.sourceforge.nekohtml:nekohtml
CVE-2021-23411 Vulnerability in npm package anchorme
CVE-2021-43090 Vulnerability in maven package com.predic8:soa-model-parent
CVE-2021-21368 Vulnerability in maven package org.webjars.npm:msgpack5