Description
rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype.
Remediation
References
https://github.com/rdf-ext-archive/rdf-graph-array/blob/master/index.js#L211
https://snyk.io/vuln/SNYK-JS-RDFGRAPHARRAY-551803
Related Vulnerabilities
CVE-2020-7743 Vulnerability in maven package org.webjars:mathjs
CVE-2017-16168 Vulnerability in npm package wffserve
CVE-2023-27602 Vulnerability in maven package org.apache.linkis:linkis-dist
CVE-2020-26256 Vulnerability in maven package org.webjars.npm:fast-csv
CVE-2023-26111 Vulnerability in npm package @nubosoftware/node-static