This affects the package json-pointer before 0.6.1. Multiple reference of object using slash is supported.
CWE-1321
CVE-2020-7713
All versions of package arr-flatten-unflatten are vulnerable to Prototype Pollution via the constructor.
CVE-2020-7714
All versions of package confucious are vulnerable to Prototype Pollution via the set function.
CVE-2020-7715
All versions of package deep-get-set are vulnerable to Prototype Pollution via the main function.
CVE-2020-7716
All versions of package deeps are vulnerable to Prototype Pollution via the set function.
CVE-2020-7717
All versions of package dot-notes are vulnerable to Prototype Pollution via the create function.