Description
think-helper defines a set of helper functions for ThinkJS. In versions of think-helper prior to 1.1.3, the software receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype. The vulnerability is patched in version 1.1.3.
Remediation
References
https://github.com/thinkjs/think-helper/security/advisories/GHSA-vr5m-3h59-7jcp
Related Vulnerabilities
CVE-2020-7729 Vulnerability in maven package org.webjars.npm:grunt
CVE-2018-3721 Vulnerability in npm package lodash
CVE-2022-40151 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2017-16126 Vulnerability in npm package botbait
CVE-2012-5817 Vulnerability in maven package org.codehaus.xfire:xfire-core