Description
This affects all versions of package mootools. This is due to the ability to pass untrusted input to Object.merge()
Remediation
References
https://snyk.io/vuln/SNYK-JS-MOOTOOLS-1325536
Related Vulnerabilities
CVE-2020-28269 Vulnerability in npm package field
CVE-2020-7686 Vulnerability in npm package rollup-plugin-dev-server
CVE-2021-32012 Vulnerability in npm package xlsx
CVE-2020-5397 Vulnerability in maven package org.springframework:spring-webflux
CVE-2021-43307 Vulnerability in maven package org.webjars.npm:semver-regex