Description
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381
Related Vulnerabilities
CVE-2019-10744 Vulnerability in maven package org.fujion.webjars:lodash
CVE-2021-23440 Vulnerability in npm package set-value
CVE-2022-31023 Vulnerability in maven package com.typesafe.play:play_2.12
CVE-2020-7795 Vulnerability in npm package get-npm-package-version
CVE-2020-28459 Vulnerability in npm package markdown-it-decorate