Vulnerabilities/

Prototype Pollution in dset

Severity:
Medium

Description

All versions of dset prior to 3.1.2 are vulnerable to Prototype Pollution via dset/merge mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or prototype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.

Recommendation

Update the dset package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
dset
Anything's wrong? Let us know Last updated on February 01, 2023