VYPR
Critical severity9.8NVD Advisory· Published Dec 29, 2020· Updated Jun 17, 2026

CVE-2020-28277

CVE-2020-28277

Description

Prototype pollution vulnerability in 'dset' versions 1.0.0 through 2.0.1 allows attacker to cause a denial of service and may lead to remote code execution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
dsetnpm
>= 1.0.0, < 2.0.12.0.1

Affected products

3
  • cpe:2.3:a:dset_project:dset:*:*:*:*:*:node.js:*:*
    Range: >=1.0.0,<=2.0.1
  • dset/dsetdescription
  • ghsa-coords
    Range: >= 1.0.0, < 2.0.1

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.