CVE-2021-44906
Published Mar 17, 2022Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
Vendor/product archive
2 CVEs tagged to substack / minimist — 1 Critical, 0 High, 1 Medium, 0 Low, 0 Unrated.
Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.