CVE-2026-107701High· 8.2▾ Twilightdot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
dot-access through 1.0.0 contains a prototype pollution vulnerability that allows attackers to modify Object.prototype by supplying a crafted dotted path to set(). Attackers controlling the path, such as through user-supplied field names, can use proto segments to inject properties into all objects, altering authorization flags and option defaults or crashing the process.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2021-23450High· 7.5All versions of package dojo are vulnerable to Prototype Pollution via the setObject function.
CVE-2021-23383Medium· 5.6The package handlebars before 4.7.7 are vulnerable to Prototype Pollution when selecting certain compiling options to compile templates coming from an untrusted source.
CVE-2020-7788High· 7.3This affects the package ini before 1.3.6
CVE-2020-5258High· 7.7In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution
CVE-2021-44906Critical· 9.8Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95).
CVE-2020-7639Medium· 5.3eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.