Affected versions of this package are vulnerable to Improper Validation of Specified Quantity in Input via unbounded precision specifiers passed without validation to the toFixed, toExponential, and toPrecision methods. An attacker who controls a format string can inject precision values exceeding ECMAScript limits, causing uncaught RangeError exceptions that abort the calling operation.