Description
All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-COMPONENTFLATTEN-548907
Related Vulnerabilities
CVE-2015-20110 Vulnerability in npm package generator-jhipster
CVE-2012-5883 Vulnerability in maven package org.webjars:yui
CVE-2023-46499 Vulnerability in npm package @evershop/evershop
CVE-2015-7559 Vulnerability in maven package org.apache.activemq:activemq-core
CVE-2021-43841 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore