Description
All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attributes to be altered, including their magical attributes such as proto, constructor and prototype.
Remediation
References
https://github.com/metabench/jsgui-lang-essentials/issues/1
https://snyk.io/vuln/SNYK-JS-JSGUILANGESSENTIALS-2316897
Related Vulnerabilities
CVE-2022-37265 Vulnerability in npm package steal
CVE-2020-8203 Vulnerability in maven package org.webjars.bower:lodash
CVE-2020-6858 Vulnerability in maven package com.hotels.styx:styx-components
CVE-2022-24066 Vulnerability in npm package simple-git
CVE-2023-36470 Vulnerability in maven package org.xwiki.platform:xwiki-platform-icon-default