Description
A prototype pollution vulnerability was found in node.extend <1.1.7, ~<2.0.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/430831
Related Vulnerabilities
CVE-2023-26106 Vulnerability in npm package dot-lens
CVE-2022-31160 Vulnerability in maven package org.fujion.webjars:jquery-ui
CVE-2021-23328 Vulnerability in npm package iniparserjs
CVE-2020-7642 Vulnerability in maven package org.webjars.bowergithub.afarkas:lazysizes
CVE-2020-8203 Vulnerability in maven package org.webjars.npm:lodash