CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.
https://www.kb.cert.org/vuls/id/458422
https://github.com/stalniy/casl/tree/master/packages/casl-ability
https://developer.mozilla.org/en-US/docs/Web/Security/Attacks/Prototype_pollution