A security scan has detected a known vulnerability (CVE-2018-16487) in the dependency lodash.clonedeep@4.5.0, which is used internally by latest Quill version.
Vulnerability details:
Package: lodash.clonedeep
Affected version: 4.5.0
CVE: CVE-2018-16487
Description: Lodash versions prior to 4.17.12 are vulnerable to Prototype Pollution, which may allow modification of object prototypes, potentially leading to unexpected behavior or security issues.
Context:
The issue was identified by an automated security scan. The vulnerability is not present in our own code but in a transitive dependency pulled in by Quill.