The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-OBJECTPATHSET-607908
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| object-path-set(npm) | 0 | 1.0.2 | N/A |
CVSS Metrics