Set In Project maintains a narrowly scoped project-management tool focused on the Set In product, with a small but durable vulnerability footprint. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Set In Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-25354CRITICAL The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to merge object prototypes into it. **Note:** This vulnerabilit | Mar 17, 2022 | 9.8 | 32 | NO | NO |
CVE-2020-28273CRITICAL Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code execution. | Dec 2, 2020 | 9.8 | 31 | NO | NO |
CVE-2026-26021CRITICAL set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (>=2.0.1, < 2.0.5). Desp | Feb 11, 2026 | 9.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Set In Project.
Media articles that mention a CVE ID that affects a product developed by Set In Project — matched by CVE ID, not by vendor name.