All the vulnerabilities related to the version 2.5.7 of the package
Prototype Pollution in json-ptr
This affects the package json-ptr
before 3.0.0
. A type confusion vulnerability can lead to a bypass of CVE-2020-7766 when the user-provided keys used in the pointer parameter are arrays.