Vulnerability library
Security checkFebruary 26, 2026

dottie is vulnerable to Prototype Pollution bypass via non-first path segments in set() and transform()

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

Medium severitynpmdottie

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

dottie versions 2.0.4 through 2.0.6 contain an incomplete fix for CVE-2023-26132. The prototype pollution guard introduced in commit 7d3aee1 only validates the first segment of a dot-separated path, allowing an attacker to bypass the protection by placing __proto__ at any position other than the first.

Both dottie.set() and dottie.transform() are affected.

Recommendation

Update the dottie package to the latest compatible version. Followings are version details:

  • Affected version(s): >= 2.0.4, <= 2.0.6
  • Patched version(s): 2.0.7

References

Could your website be exposed too?

SmartScanner can check your website for dottie is vulnerable to Prototype Pollution bypass via non-first path segments in set() and transform() and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated February 26, 2026