Prototype pollution vulnerability in nconf-toml versions 0.0.1 through 0.0.2 allows an attacker to cause a denial of service and may lead to remote code execution.
nconf-toml
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-25946.json"