CVE-2022-25645: Dset Project Dset
High severity, CVSS 8.1. EPSS: 1.8% chance of exploitation in the next 30 days.
All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.
Affected products
- Dset Project Dset: any version
Published 2022-05-01. Last modified 2026-06-17.