Description
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381
Related Vulnerabilities
CVE-2021-34801 Vulnerability in npm package valine
CVE-2023-37943 Vulnerability in maven package org.jenkins-ci.plugins:active-directory
CVE-2017-16131 Vulnerability in npm package unicorn-list
CVE-2023-30547 Vulnerability in npm package vm2
CVE-2022-42466 Vulnerability in maven package org.apache.isis.core:isis-applib