minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
https://github.com/1816x/Vulnerability-Triage-Agent
https://github.com/renewablehacking/CVE-2020-7598
https://github.com/riddhinsanghvi/CVE_Patch_Finder
https://github.com/mlbrilliance/aurora-demo-lockfile
https://github.com/fabriziosalmi/gitoma-bench-supply-chain
https://github.com/amitgandole-tal/nodejs-cve
https://github.com/advisories/GHSA-vh95-rmgr-6w4m
https://snyk.io/vuln/SNYK-JS-MINIMIST-559764
http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html