Description
A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/390860
Related Vulnerabilities
CVE-2018-3728 Vulnerability in maven package org.webjars.npm:hoek
CVE-2020-11987 Vulnerability in maven package org.apache.xmlgraphics:batik-svgbrowser
CVE-2022-0155 Vulnerability in npm package follow-redirects
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http_2.12
CVE-2020-7616 Vulnerability in npm package express-mock-middleware