Vulnerabilities/

@rvf/set-get has a prototype pollution issue that's reachable via @rvf/core preprocessFormData (HTTP form data)

Severity:
High

Description

setPath in @rvf/set-get (used by @rvf/core to flatten incoming form data into a nested object) does not block the keys __proto__, constructor, or prototype when walking a path.

Recommendation

Update the @rvf/set-get package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
@rvf/set-get
Anything's wrong? Let us know Last updated on June 08, 2026