Description
A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/381185
Related Vulnerabilities
CVE-2020-36649 Vulnerability in npm package papaparse
CVE-2023-24807 Vulnerability in npm package undici
CVE-2017-16017 Vulnerability in npm package sanitize-html
CVE-2021-32770 Vulnerability in npm package gatsby-source-wordpress
CVE-2023-49653 Vulnerability in maven package org.jenkins-ci.plugins:jira