CPE
The @socket.io/cluster-engine package is vulnerable to prototype pollution when processing attacker-controlled session IDs, allowing an attacker to cause a denial of service via process crash.