Description
utilitify prior to 1.0.3 allows modification of object properties. The merge method could be tricked into adding or modifying properties of the Object.prototype.
Remediation
References
https://github.com/xcritical-software/utilitify/commit/88d6e27009823338bf319ffb768fe6b08e8ad2d1%2C
https://snyk.io/vuln/SNYK-JS-UTILITIFY-559497
Related Vulnerabilities
CVE-2017-16176 Vulnerability in npm package jansenstuffpleasework
CVE-2023-29213 Vulnerability in maven package org.xwiki.platform:xwiki-platform-logging-script
CVE-2018-21270 Vulnerability in npm package stringstream
CVE-2018-20822 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2020-28471 Vulnerability in npm package properties-reader