ZeroHour

CVE-2023-26132

PoC
CVSS 3.1
7.5 high
EPSS
1%p63
Published
()
Modified
Description

Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the set() function and the current variable in the /dottie.js file.

Vendors
dottie project
Products
dottie
Weakness
CWE-1321
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.