vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| vega-util(npm) | 0 | 1.13.1 | N/A |
CVSS Metrics