Description
Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.
Remediation
References
https://github.com/kvz/locutus/pull/418/
https://snyk.io/vuln/SNYK-JS-LOCUTUS-598675
Related Vulnerabilities
CVE-2022-22984 Vulnerability in npm package snyk-sbt-plugin
CVE-2019-18212 Vulnerability in maven package org.lsp4xml:org.eclipse.lsp4xml.extensions.emmet
CVE-2020-9484 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2021-25914 Vulnerability in npm package object-collider
CVE-2022-22984 Vulnerability in npm package snyk-gradle-plugin