The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: version 0.10.0 is a breaking change removing the vulnerable functions.
{
"severity": "HIGH",
"github_reviewed_at": "2020-09-14T21:41:51Z",
"cwe_ids": [
"CWE-1321",
"CWE-915"
],
"nvd_published_at": "2020-09-01T10:15:00Z",
"github_reviewed": true
}