Description
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
Remediation
References
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html
https://snyk.io/vuln/SNYK-JS-MINIMIST-559764
Related Vulnerabilities
CVE-2022-38750 Vulnerability in maven package org.yaml:snakeyaml
CVE-2019-14863 Vulnerability in npm package angular
CVE-2022-0086 Vulnerability in npm package uppy
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http-core_2.12
CVE-2023-46497 Vulnerability in npm package @evershop/evershop