Full threadzacharyvoase·If this is a CVE, then arguably any method invocation on any function argument in any JavaScript library is a CVE, and we might as well throw the whole thing away. Is there a way to challenge this as not-a-CVE?View on HN