Description
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381
Related Vulnerabilities
CVE-2020-17516 Vulnerability in maven package org.apache.cassandra:cassandra-all
CVE-2021-32808 Vulnerability in npm package ckeditor4
CVE-2021-4264 Vulnerability in maven package org.webjars:dustjs-linkedin
CVE-2020-28268 Vulnerability in npm package controlled-merge
CVE-2023-43496 Vulnerability in maven package org.jenkins-ci.main:jenkins-core