Vendorsset-value Projectset-valueall versions
Vulnerabilities

set-value Project set-value

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2019-10747
set-value is vulnerable to Prototype Pollution in versions lower than 3.0.1. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using any of the constructor, prototype and _proto_ payloads.
Published 2019-08-23 · Modified
9.8EPSS 0.025
CVE-2021-23440
Prototype Pollution
Published 2021-09-12 · Modified
9.8EPSS 0.022