Aurelia-path before 1.1.7 contains a prototype pollution caused by parsing malicious URL parameters, letting attackers modify Object.prototype, exploit requires the application to parse user-controlled URLs.
id: CVE-2021-41097
info:
name: Aurelia-Path < 1.1.7 - Prototype Pollution
author: 0x_Akoko
se
...