Description
All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attributes to be altered, including their magical attributes such as proto, constructor and prototype.
Remediation
References
https://github.com/metabench/jsgui-lang-essentials/issues/1
https://snyk.io/vuln/SNYK-JS-JSGUILANGESSENTIALS-2316897
Related Vulnerabilities
CVE-2020-28469 Vulnerability in npm package glob-parent
CVE-2020-15119 Vulnerability in maven package org.webjars.npm:auth0-lock
CVE-2017-16021 Vulnerability in npm package uri-js
CVE-2020-36188 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2023-46496 Vulnerability in npm package @evershop/evershop