Description
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
Remediation
References
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html
https://snyk.io/vuln/SNYK-JS-MINIMIST-559764
Related Vulnerabilities
CVE-2022-31167 Vulnerability in maven package org.xwiki.platform:xwiki-platform-security
CVE-2019-10416 Vulnerability in maven package org.jenkins-ci.plugins:violation-comments-to-gitlab
CVE-2023-26487 Vulnerability in npm package vega
CVE-2022-24373 Vulnerability in npm package react-native-reanimated
CVE-2020-1948 Vulnerability in maven package org.apache.dubbo:dubbo-rpc-api