sindresorhus/dot-prop

sindresorhus/dot-prop

Releases31
Frequency4 months 1 week
Last Release
Stars866
Get, set, or delete a property from a nested object using a dot path

CVE History

CVEPublishedCVSS v3CVSS v2
7.3 HIGH7.5 HIGH

Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language constructs such as objects.