Description
All versions of component-flatten are vulnerable to Prototype Pollution. The a function could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-COMPONENTFLATTEN-548907
Related Vulnerabilities
CVE-2017-1000452 Vulnerability in npm package samlify
CVE-2023-26045 Vulnerability in npm package nodebb
CVE-2022-1365 Vulnerability in npm package cross-fetch
CVE-2021-24033 Vulnerability in maven package org.webjars.npm:react-dev-utils
CVE-2022-43427 Vulnerability in maven package com.compuware.jenkins:compuware-topaz-for-total-test