All versions of package node-forge are vulnerable to Prototype Pollution via the util.setPath function.