Description
rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype.
Remediation
References
https://github.com/rdf-ext-archive/rdf-graph-array/blob/master/index.js#L211
https://snyk.io/vuln/SNYK-JS-RDFGRAPHARRAY-551803
Related Vulnerabilities
CVE-2019-5485 Vulnerability in npm package gitlabhook
CVE-2021-23375 Vulnerability in npm package psnode
CVE-2021-41038 Vulnerability in npm package @theia/plugin-ext
CVE-2022-22931 Vulnerability in maven package org.apache.james:james-server
CVE-2023-34840 Vulnerability in npm package angular-ui-notification