Webpack · Loader-Utils · CVE-2022-37601
**Name of the Vulnerable Software and Affected Versions**
loader-utils versions prior to 1.4.1
loader-utils versions prior to 2.0.3
**Description**
The issue is related to a prototype pollution vulnerability in the `parseQuery` function within `parseQuery.js` in webpack loader-utils. This vulnerability is exploited via the `name` variable in `parseQuery.js`.
**Recommendations**
For versions prior to 1.4.1, update to version 1.4.1 or later.
For versions prior to 2.0.3, update to version 2.0.3 or later.