Description
A prototype pollution vulnerability was found in module mpath <0.5.1 that allows an attacker to inject arbitrary properties onto Object.prototype.
Remediation
References
https://hackerone.com/reports/390860
Related Vulnerabilities
CVE-2021-25948 Vulnerability in npm package expand-hash
CVE-2020-8244 Vulnerability in maven package org.webjars.npm:bl
CVE-2018-16487 Vulnerability in maven package org.webjars.npm:lodash.merge
CVE-2019-13343 Vulnerability in maven package com.butor:portal
CVE-2018-5673 Vulnerability in maven package org.dojotoolkit:dojo