Description
This affects the package open-graph before 0.2.6. The function parse could be tricked into adding or modifying properties of Object.prototype using a __proto__ or constructor payload.
Remediation
References
https://github.com/samholmes/node-open-graph/commit/a0cef507a90adaac7dbbe9c404f09a50bdefb348
https://snyk.io/vuln/SNYK-JS-OPENGRAPH-1536747
Related Vulnerabilities
CVE-2016-10735 Vulnerability in maven package org.webjars.bowergithub.jasny:bootstrap
CVE-2013-4444 Vulnerability in maven package org.apache.tomcat.embed:tomcat-embed-core
CVE-2022-39299 Vulnerability in npm package node-saml
CVE-2016-4000 Vulnerability in maven package org.python:jython-standalone
CVE-2021-41532 Vulnerability in maven package org.apache.ozone:ozone-recon