Description
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381
Related Vulnerabilities
CVE-2019-10793 Vulnerability in npm package dot-object
CVE-2020-28464 Vulnerability in npm package djv
CVE-2021-44908 Vulnerability in npm package sails
CVE-2022-35961 Vulnerability in maven package org.webjars.npm:openzeppelin__contracts-upgradeable
CVE-2022-3509 Vulnerability in maven package com.google.protobuf:protobuf-java