CVE-2023-26132: Dottie Project Dottie
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the set() function and the current variable in the /dottie.js file.
Affected products
- Dottie Project Dottie: before 2.0.4 (fixed in 2.0.4)
Published 2023-06-10. Last modified 2026-06-17.