Description
Flaw in input validation in npm package klona version 1.1.0 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using klona.
Remediation
References
https://hackerone.com/reports/778414
Related Vulnerabilities
CVE-2023-45134 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2023-37476 Vulnerability in maven package org.openrefine:main
CVE-2021-23352 Vulnerability in npm package madge
CVE-2023-26136 Vulnerability in maven package org.webjars.npm:tough-cookie
CVE-2020-28459 Vulnerability in npm package markdown-it-decorate