The package property-expr before 2.0.3 are vulnerable to Prototype Pollution via the setter function.
{
"source": [
"CPE_FIELD",
"REFERENCES"
],
"cpe": "cpe:2.3:a:property-expr_project:property-expr:*:*:*:*:*:node.js:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.0.3"
}
]
}