Description
All versions of the package rangy are vulnerable to Prototype Pollution when using the extend() function in file rangy-core.js.The function uses recursive merge which can lead an attacker to modify properties of the Object.prototype
Remediation
References
https://github.com/timdown/rangy/issues/478
https://security.snyk.io/vuln/SNYK-JS-RANGY-3175702
Related Vulnerabilities
CVE-2021-23330 Vulnerability in npm package launchpad
CVE-2020-12265 Vulnerability in npm package decompress
CVE-2021-23820 Vulnerability in npm package json-pointer
CVE-2021-46036 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2019-14653 Vulnerability in maven package org.webjars.bowergithub.pandao:editor.md