Versions of the package tough-cookie before 4.1.3 are vulnerable to Prototype Pollution due to improper handling of Cookies when using CookieJar in rejectPublicSuffixes=false mode. This issue arises from the manner in which the objects are initialized.
{
"nvd_published_at": "2023-07-01T05:15:16Z",
"github_reviewed_at": "2023-07-07T21:39:57Z",
"cwe_ids": [
"CWE-1321"
],
"severity": "MODERATE",
"github_reviewed": true
}