Lucene search

K
osvGoogleOSV:GHSA-23WX-CGXQ-VPWX
HistoryMay 03, 2022 - 12:00 a.m.

Prototype Pollution in dset

2022-05-0300:00:45
Google
osv.dev
6

0.005 Low

EPSS

Percentile

76.1%

All versions of dset prior to 3.1.2 are vulnerable to Prototype Pollution via dset/merge mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or prototype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

0.005 Low

EPSS

Percentile

76.1%