lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., proto) can be copied during a merge or clone operation.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-35149.json"