Vulnerabilities/

Prototype Pollution in set-or-get

Severity:
High

Description

Prototype pollution vulnerability in ‘set-or-get’ version 1.0.0 through 1.2.10 allows an attacker to cause a denial of service and may lead to remote code execution.

Recommendation

Update the set-or-get package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
set-or-get
Anything's wrong? Let us know Last updated on February 01, 2023