Flaw in input validation in npm package utils-extend version 1.0.8 and earlier may allow prototype pollution attack that may result in remote code execution or denial of service of applications using utils-extend.
- https://hackerone.com/reports/801522
- https://github.com/ErikHorus1249/CVE_DOC
- https://github.com/LittleZen/Hastemail