minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "proto" payload.
| Software | From | Fixed in |
|---|---|---|
| substack / minimist | - | 1.2.2 |
| opensuse / leap | 15.1 | 15.1.x |
minimist
|
- | 0.2.1 |
minimist
|
1.0.0 | 1.2.3 |