Description
This affects all versions of package x-assign. The global proto object can be polluted using the __proto__ object.
Remediation
References
https://runkit.com/embed/sq8qjwemyn8t
https://snyk.io/vuln/SNYK-JS-XASSIGN-1759314
Related Vulnerabilities
CVE-2019-16763 Vulnerability in npm package pannellum
CVE-2023-34840 Vulnerability in npm package angular-ui-notification
CVE-2015-5262 Vulnerability in maven package org.apache.httpcomponents:httpclient
CVE-2017-7545 Vulnerability in maven package org.jbpm:jbpm-designer-backend
CVE-2023-26488 Vulnerability in npm package @openzeppelin/contracts