Description
This affects all versions of package nedb. The library could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor.prototype payload.
Remediation
References
https://snyk.io/vuln/SNYK-JS-NEDB-1305279
Related Vulnerabilities
CVE-2022-1233 Vulnerability in npm package urijs
CVE-2022-22965 Vulnerability in maven package org.springframework:spring-webflux
CVE-2019-20149 Vulnerability in maven package org.webjars.npm:kind-of
CVE-2021-27516 Vulnerability in npm package urijs
CVE-2023-44487 Vulnerability in maven package io.netty:netty-codec-http2