Skip to main content

Vendor/product archive

set-in_project / set-in CVEs

Beta · best-effort

3 CVEs tagged to set-in_project / set-in2 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2026-26021

Published Feb 11, 2026

set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (>=2.0.1, < 2.0.5). Des…

CVSS 9.4 · Critical
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2022-25354

Published Mar 17, 2022

The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to merge object prototypes into it. **Note:** This vulnerabili…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28273

Published Dec 2, 2020

Prototype pollution vulnerability in 'set-in' versions 1.0.0 through 2.0.0 allows attacker to cause a denial of service and may lead to remote code execution.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1