Dot Prop Project maintains a single, narrowly scoped utility library for nested object property access and manipulation in JavaScript environments. The limited disclosure history reflects the focused scope of the project and its role as a small, embedded dependency rather than a broad platform. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dot Prop Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8116HIGH Prototype pollution vulnerability in dot-prop npm package versions before 4.2.1 and versions 5.x before 5.1.1 allows an attacker to add arbitrary properties to JavaScript language | Feb 4, 2020 | 7.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dot Prop Project.
Media articles that mention a CVE ID that affects a product developed by Dot Prop Project — matched by CVE ID, not by vendor name.