Description
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
Remediation
References
https://snyk.io/vuln/SNYK-JS-MOOTOOLS-1325536
Related Vulnerabilities
CVE-2023-26115 Vulnerability in maven package org.webjars.npm:word-wrap
CVE-2020-28442 Vulnerability in npm package js-data
CVE-2021-23337 Vulnerability in maven package org.webjars:lodash
CVE-2020-27223 Vulnerability in maven package org.eclipse.jetty:jetty-server
CVE-2020-7712 Vulnerability in maven package org.webjars.npm:json