CVE-2024-21529

HIGH

dset < 3.1.4 - Prototype Pollution via __proto__ Property Injection

Title source: llm
STIX 2.1

Description

Versions of the package dset before 3.1.4 are vulnerable to Prototype Pollution via the dset function due improper user input sanitization. This vulnerability allows the attacker to inject malicious object property using the built-in Object property __proto__, which is recursively assigned to all the objects in the program.

Scores

CVSS v3 8.2
EPSS 0.0062
EPSS Percentile 44.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-1321
Status published
Products (2)
n/a/dset < 3.1.4
npm/dset 0 - 3.1.4npm
Published Sep 11, 2024
Tracked Since Feb 18, 2026