Логотип exploitDog
bind:CVE-2026-26021
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-26021

Количество 2

Количество 2

nvd логотип

CVE-2026-26021

около 2 месяцев назад

set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (>=2.0.1, < 2.0.5). Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using Array.prototype. This has been fixed in version 2.0.5.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-2c4m-g7rx-63q7

около 2 месяцев назад

set-in Affected by Prototype Pollution

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-26021

set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (>=2.0.1, < 2.0.5). Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using Array.prototype. This has been fixed in version 2.0.5.

CVSS3: 9.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-2c4m-g7rx-63q7

set-in Affected by Prototype Pollution

0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу