Description
Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Object property proto, which is recursively assigned to all the objects in the program.
Recommendation
Update the dset package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.1.4
- Patched version(s): 3.1.4
References
Related Issues
- uPlot Prototype Pollution vulnerability - CVE-2024-21489
- @cat5th/key-serializer Prototype Pollution vulnerability - CVE-2024-39018
- Conform contains a Prototype Pollution Vulnerability in `parseWith...` function - CVE-2024-32866
- Conform contains a Prototype Pollution Vulnerability in `parseWith...` function - @conform-to/zod - CVE-2024-32866
You might also like:
- Tags:
- npm
- dset
Anything's wrong? Let us know Last updated on September 11, 2024


