Skip to main content

Vendor/product archive

dottie_project / dottie CVEs

Beta · best-effort

2 CVEs tagged to dottie_project / dottie0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-27837

Published Feb 26, 2026

Dottie provides nested object access and manipulation in JavaScript. Versions 2.0.4 through 2.0.6 contain an incomplete fix for CVE-2023-26132. The prototype pollution guard intro…

CVSS 6.3 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2023-26132

Published Jun 10, 2023

Versions of the package dottie before 2.0.4 are vulnerable to Prototype Pollution due to insufficient checks, via the set() function and the current variable in the /dottie.js fil…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1