CVE-2022-25862

MEDIUM

sds - Prototype Pollution via set Function

Title source: llm
STIX 2.1

Description

This affects the package sds from 0.0.0. The library could be tricked into adding or modifying properties of the Object.prototype by abusing the set function located in js/set.js. **Note:** This vulnerability derives from an incomplete fix to [CVE-2020-7618](https://security.snyk.io/vuln/SNYK-JS-SDS-564123)

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-SDS-2385944

Scores

CVSS v3 4.0
EPSS 0.0069
EPSS Percentile 47.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L

Details

CWE
CWE-1321
Status published
Products (2)
npm/sds 0npm
sds_project/sds
Published May 13, 2022
Tracked Since Feb 18, 2026