Description
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
Remediation
References
https://snyk.io/vuln/SNYK-JS-MOOTOOLS-1325536
Related Vulnerabilities
CVE-2020-8116 Vulnerability in npm package dot-prop
CVE-2019-15138 Vulnerability in npm package html-pdf
CVE-2022-25923 Vulnerability in npm package exec-local-bin
CVE-2023-30465 Vulnerability in maven package org.apache.inlong:manager-service
CVE-2022-40309 Vulnerability in maven package org.apache.archiva:maven2-repository