Path : nodemailer-sparkpost-transport > sparkpost > lodash
Version : "nodemailer-sparkpost-transport": "^2.2.0"
NPM security warning:
Overview
Versions of lodash before 4.17.12 are vulnerable to Prototype Pollution. The function defaultsDeep allows a malicious user to modify the prototype of Object via {constructor: {prototype: {...}}} causing the addition or modification of an existing property that will exist on all objects.
Remediation
Update to version 4.17.12 or later.