vega-util prior to 1.13.1 allows manipulation of object prototype. The ‘vega.mergeConfig’ method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
[
{
"product": "vega-util",
"vendor": "n/a",
"versions": [
{
"status": "affected",
"version": "All versions prior to 1.13.1"
}
]
}
]