Description
All versions of package querymen are vulnerable to Prototype Pollution if the parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. Note: This vulnerability derives from an incomplete fix of [CVE-2020-7600](https://security.snyk.io/vuln/SNYK-JS-QUERYMEN-559867).
Remediation
References
https://snyk.io/vuln/SNYK-JS-QUERYMEN-2391488
Related Vulnerabilities
CVE-2023-26486 Vulnerability in npm package vega-functions
CVE-2021-23771 Vulnerability in npm package notevil
CVE-2016-3081 Vulnerability in maven package org.apache.struts:struts2-core
CVE-2022-4111 Vulnerability in npm package tooljet
CVE-2023-29216 Vulnerability in maven package org.apache.linkis:linkis-engineplugin-jdbc