Skip to content

[GHSA-f6v4-cf5j-vf3w] dset Prototype Pollution vulnerability#7460

Open
Wenxin-Jiang wants to merge 2 commits intoWenxin-Jiang/advisory-improvement-7460from
Wenxin-Jiang-GHSA-f6v4-cf5j-vf3w
Open

[GHSA-f6v4-cf5j-vf3w] dset Prototype Pollution vulnerability#7460
Wenxin-Jiang wants to merge 2 commits intoWenxin-Jiang/advisory-improvement-7460from
Wenxin-Jiang-GHSA-f6v4-cf5j-vf3w

Conversation

@Wenxin-Jiang
Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3

Comments
The vulnerable keys[i] assignment sink is first introduced in 1.0.0's dist/dset.js. 0.0.0 cannot express the prototype-pollution vulnerability because it exports no code.

@github-actions github-actions bot changed the base branch from main to Wenxin-Jiang/advisory-improvement-7460 April 20, 2026 16:12
@Wenxin-Jiang
Copy link
Copy Markdown
Author

Note that the v3 severity removal in this PR is an artifact of the improvement-form serializer, not intentional — feel free to restore it on merge.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant