VDB
Sign up
HIGH8.2

GHSA-f6v4-cf5j-vf3w

dset Prototype Pollution vulnerability

Quick fix

GHSA-f6v4-cf5j-vf3w — dset: upgrade to the fixed version with the command below.

npm install dset@3.1.4

Details

Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Object property __proto__, which is recursively assigned to all the objects in the program.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/dset
Introduced in: 0Fixed in: 3.1.4
Fixnpm install dset@3.1.4

References