Prototype Pollution in object-path-set
High severity
GitHub Reviewed
Published
Feb 5, 2022
to the GitHub Advisory Database
•
Updated Feb 3, 2023
Description
Published by the National Vulnerability Database
Feb 4, 2022
Published to the GitHub Advisory Database
Feb 5, 2022
Reviewed
Feb 7, 2022
Last updated
Feb 3, 2023
The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. Note: This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-OBJECTPATHSET-607908
References