mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
[
{
"product": "mixin-deep",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "All versions before 1.3.2 and version 2.0.0."
}
]
}
]
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFNIVG2XYFPZJY3DYYBJASZ7ZMKBMIJT/
lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UXRA365KZCUNXMU3KDH5JN5BEPNIGUKC/
snyk.io/vuln/SNYK-JS-MIXINDEEP-450212
www.oracle.com//security-alerts/cpujul2021.html