Description
Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.0 there was a prototype pollution vulnerability in the internal utility method "lib/utils/object/set.ts". This method is used throughout the codebase for various operations throughout Dynamoose. We have not seen any evidence of this vulnerability being exploited. There is no evidence this vulnerability impacts versions 1.x.x since the vulnerable method was added as part of the v2 rewrite. This vulnerability also impacts v2.x.x beta/alpha versions. Version 2.7.0 includes a patch for this vulnerability.
References (4)
Core 4
Core References
Patch, Third Party Advisory x_refsource_confirm
https://github.com/dynamoose/dynamoose/security/advisories/GHSA-rrqm-p222-8ph2
Patch, Third Party Advisory x_refsource_misc
https://github.com/dynamoose/dynamoose/commit/324c62b4709204955931a187362f8999805b1d8e
Release Notes, Third Party Advisory x_refsource_misc
https://github.com/dynamoose/dynamoose/releases/tag/v2.7.0
Product, Third Party Advisory x_refsource_misc
https://www.npmjs.com/package/dynamoose
Scores
CVSS v3
7.2
EPSS
0.0189
EPSS Percentile
76.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Details
CWE
CWE-915
CWE-1321
Status
published
Products (2)
dynamoosejs/dynamoose
2.0.0 - 2.7.0
npm/dynamoose
2.0.0 - 2.7.0npm
Published
Feb 08, 2021
Tracked Since
Feb 18, 2026