A vulnerability was found in querystringify before 2.0.0. It's possible to override built-in properties of the resulting query string object if a malicious string is inserted in the query string.
{ "github_reviewed_at": "2019-06-07T21:11:35Z", "cwe_ids": [ "CWE-1321" ], "nvd_published_at": null, "severity": "HIGH", "github_reviewed": true }