A prototype pollution vulnerability in the min-document package allows attackers to manipulate JavaScript object prototypes via improper handling of namespace operations in the removeAttributeNS ...