CVE-2019-10806: Improperly Controlled Modification of Dynamically-Determined Object Attributes
(updated )
vega-util allows manipulation of object prototype. The ‘vega.mergeConfig’ method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
References
Detect and mitigate CVE-2019-10806 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →