depath and cool-path vulnerable to Prototype Pollution via `set()` Method - depath
- Severity:
- High
Description
janryWang products depath v1.0.6 and cool-path v1.1.2 were discovered to contain a prototype pollution via the set() method at setIn (lib/index.js:90). This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.0.6
References
Related Issues
- depath and cool-path vulnerable to Prototype Pollution via `set()` Method - CVE-2024-38985
- dottie is vulnerable to Prototype Pollution bypass via non-first path segments in set() and transform() - CVE-2026-27837
- lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - CVE-2026-2950
- lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - lodash.unset - CVE-2026-2950
You might also like:
- Tags:
- npm
- depath
Anything's wrong? Let us know Last updated on March 31, 2025


