vega-util prior to 1.13.1 allows manipulation of object prototype. The 'vega.mergeConfig' method within vega-util could be tricked into adding or modifying properties of the Object.prototype.
| Software | From | Fixed in |
|---|---|---|
| vega_project / vega | - | 1.13.1 |
vega-util
|
- | 1.13.1 |