Description
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-NEDB-1305279
Related Vulnerabilities
CVE-2022-31160 Vulnerability in maven package org.webjars.npm:jquery-ui
CVE-2023-33725 Vulnerability in maven package org.broadleafcommerce:broadleaf
CVE-2022-0671 Vulnerability in maven package org.eclipse.lemminx:lemminx-parent
CVE-2020-7684 Vulnerability in npm package rollup-plugin-serve
CVE-2020-23262 Vulnerability in maven package net.mingsoft:ms-mcms