Severity: Critical
CVSS Score: 9.8
All versions of package node-oojs are vulnerable to Prototype Pollution via the setPath function.