strikeentco/set

strikeentco/set

Releases0
Stars3
Set nested values on an object using a dot path or custom separator

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH7.5 HIGH

This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. **Note:** This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821

7.5 HIGH5 MEDIUM

Prototype pollution vulnerability in '@strikeentco/set' version 1.0.0 allows attacker to cause a denial of service and may lead to remote code execution.