Prototype Manipulation Vulnerability in Vega-Util by Vega
CVE-2019-10806
4.3MEDIUM
What is CVE-2019-10806?
Versions of vega-util earlier than 1.13.1 are susceptible to a vulnerability that allows for manipulation of the Object.prototype. This manipulation can occur through the 'vega.mergeConfig' method, which can be exploited to add or modify properties of the prototype, potentially leading to unexpected behavior in applications utilizing this package. Developers should ensure they are using an updated version to mitigate this risk.
Affected Version(s)
vega-util All versions prior to 1.13.1