Affected versions of @polymer/polymer are vulnerable to prototype pollution. The package fails to prevent modification of object prototypes through chart options containing a payload such as {"__proto__": {"polluted": true}}. It is possible to achieve the same results if a chart loads data from a malicious server.
Upgrade to version 3.2.0 or later.
{
"severity": "HIGH",
"nvd_published_at": "2019-11-11T01:15:00Z",
"github_reviewed_at": "2019-11-27T02:43:23Z",
"github_reviewed": true,
"cwe_ids": []
}