Description
Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona.
Remediation
References
https://hackerone.com/reports/778414
Related Vulnerabilities
CVE-2017-16096 Vulnerability in npm package serveryaozeyan
CVE-2022-1365 Vulnerability in npm package cross-fetch
CVE-2023-38691 Vulnerability in npm package matrix-appservice-bridge
CVE-2020-26256 Vulnerability in npm package fast-csv
CVE-2023-29213 Vulnerability in maven package org.xwiki.platform:xwiki-platform-logging-script