Prototype pollution vulnerability in the TypeORM package < 0.2.25 may allow attackers to add or modify Object properties leading to further denial of service or SQL injection attacks.
https://hackerone.com/reports/869574
https://hackerone.com/reports/869574
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8158