Critical severity9.8NVD Advisory· Published Dec 29, 2020· Updated Jun 17, 2026
CVE-2020-28276
CVE-2020-28276
Description
Prototype pollution vulnerability in 'deep-set' versions 1.0.0 through 1.0.1 allows attacker to cause a denial of service and may lead to remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
deep-setnpm | >= 1.0.0, <= 1.0.1 | — |
Affected products
3- cpe:2.3:a:deep-set_project:deep-set:*:*:*:*:*:node.js:*:*Range: >=1.0.0,<=1.0.1
- deep-set/deep-setdescription
Patches
Vulnerability mechanics
References
5- github.com/klaemo/deep-set/blob/103d650b3de1f5c6cf051236347ba59e7274cd07/index.jsnvdExploitThird Party AdvisoryWEB
- www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28276nvdExploitThird Party Advisory
- github.com/advisories/GHSA-wgxm-rg53-h2c6ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-28276ghsaADVISORY
- web.archive.org/web/20210320110509/https://www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28276ghsaWEB
News mentions
0No linked articles in our index yet.