An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS1tampqLTZwNDMtdmhods4AAs9_

High CVSS: 7.5 EPSS: 0.00247% (0.47948 Percentile) EPSS:

Prototype Pollution in deep-get-set

Affected Packages Affected Versions Fixed Versions
npm:deep-get-set
PURL: pkg:npm/deep-get-set
<= 1.1.1 No known fixed version
50 Dependent packages
166 Dependent repositories
17,661 Downloads last month

Affected Version Ranges

All affected versions

0.1.0, 0.1.1, 1.0.0, 1.1.0, 1.1.1

All versions of package deep-get-set are vulnerable to Prototype Pollution via the 'deep' function. Note: This vulnerability derives from an incomplete fix of CVE-2020-7715

References: