MEDIUM6.5
GHSA-23wx-cgxq-vpwx
Prototype Pollution in dset
Quick fix
GHSA-23wx-cgxq-vpwx — dset: upgrade to the fixed version with the command below.
npm install dset@3.1.2Details
All versions of `dset` prior to 3.1.2 are vulnerable to Prototype Pollution via `dset/merge` mode, as the `dset` function checks for prototype pollution by validating if the top-level path contains `__proto__`, `constructor` or `prototype`. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.webjars.npm:dset
Introduced in:
0Fixed in: 3.1.2Fix
# pom.xml: bump <version>3.1.2</version> for org.webjars.npm:dset