rdf-graph-array through 0.3.0-rc6 manipulation of JavaScript objects resutling in Prototype Pollution. The rdf.Graph.prototype.add method could be tricked into adding or modifying properties of Object.prototype.
Link | Tags |
---|---|
https://github.com/rdf-ext-archive/rdf-graph-array/blob/master/index.js#L211 | tool signature exploit |
https://snyk.io/vuln/SNYK-JS-RDFGRAPHARRAY-551803 | third party advisory |