Dset Project maintains a focused JavaScript-oriented toolkit where the durable vulnerability signal centers on prototype-pollution issues in object-modification code paths. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dset Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25645HIGH All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path co | May 1, 2022 | 8.1 | 26 | NO | NO |
CVE-2020-28277CRITICAL Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution. | Dec 29, 2020 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dset Project.
Media articles that mention a CVE ID that affects a product developed by Dset Project — matched by CVE ID, not by vendor name.