In AngularJS before 1.7.9 the function merge() could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.
| Software | From | Fixed in |
|---|---|---|
@schematics / angular
|
- | 1.7.9 |
| angularjs / angularjs | - | 1.7.9 |