Description
yargs-parser could be tricked into adding or modifying properties of Object.prototype using a "__proto__" payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381
Related Vulnerabilities
CVE-2019-18212 Vulnerability in maven package org.lsp4xml:org.eclipse.lsp4xml.extensions.emmet
CVE-2022-43414 Vulnerability in maven package org.jenkins-ci.plugins:nunit
CVE-2020-6428 Vulnerability in npm package electron
CVE-2015-1427 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2023-49299 Vulnerability in maven package org.apache.dolphinscheduler:dolphinscheduler-master