Description
All versions of package jsgui-lang-essentials are vulnerable to Prototype Pollution due to allowing all Object attributes to be altered, including their magical attributes such as proto, constructor and prototype.
Remediation
References
https://github.com/metabench/jsgui-lang-essentials/issues/1
https://snyk.io/vuln/SNYK-JS-JSGUILANGESSENTIALS-2316897
Related Vulnerabilities
CVE-2023-26116 Vulnerability in npm package angular
CVE-2023-26487 Vulnerability in maven package org.webjars.bowergithub.vega:vega
CVE-2021-25913 Vulnerability in npm package set-or-get
CVE-2023-31580 Vulnerability in maven package com.networknt:light-oauth2
CVE-2023-40350 Vulnerability in maven package org.jenkins-ci.plugins:docker-swarm