CVEs affecting projects tracked on Release Alert, from NVD & OSV.
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.