The bug itself doesn't enable any of those. An app using the library might have that vuln.
I see a lot of critical (9+) supposed JavaScript "remote code execution with no authentication" CVEs being posted...
Right, if you are running it in an NPM server exposed to malicious user input with no authentication. Actually it runs client side in the browser and at best it's a prototype pollution vuln with a much lower score.
The above is a motto for the entire vulnerability industrial complex.
It might be right, but it also feels so wrong.
I would in reality probably rank this issue lower. And in some more properly engineered systems it would have lot less criticality.
> someone could theoretically use the tool
makes every single logic error a 9.9