fullPage utils are available to developers using window.fp_utils. They can use these utils for their own use-case (other than fullPage) as well. However, one of the utils deepExtend is vulnerable to Prototype Pollution vulnerability.
Javascript is "prototype" language which means when a new "object" is created, it carries the predefined properties and methods of an "object" with itself like toString, constructor etc. By using prototype-pollution vulnerability, an attacker can overwrite/create the property of that "object" type. If the victim developer has used that property anywhere in the code, then it will have severe effect on the application.
{ "nvd_published_at": "2022-04-11T12:15:00Z", "github_reviewed_at": "2022-04-22T20:20:05Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-1321" ] }