Description
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-NEDB-1305279
Related Vulnerabilities
CVE-2020-7226 Vulnerability in maven package org.cryptacular:cryptacular
CVE-2023-26049 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2023-45134 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2021-20289 Vulnerability in maven package org.jboss.resteasy:resteasy-core