Critical severity9.8NVD Advisory· Published Dec 29, 2020· Updated Jun 17, 2026
CVE-2020-28281
CVE-2020-28281
Description
Prototype pollution vulnerability in 'set-object-value' versions 0.0.0 through 0.0.5 allows an attacker to cause a denial of service and may lead to remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
set-object-valuenpm | < 0.0.6 | 0.0.6 |
Affected products
3- cpe:2.3:a:set-object-value_project:set-object-value:*:*:*:*:*:node.js:*:*Range: >=0.0.0,<=0.0.5
- set-object-value/set-object-valuedescription
Patches
Vulnerability mechanics
References
4- github.com/react-atomic/react-atomic-organism/blob/e5645a2f9e632ffdebc83d720498831e09754c22/packages/lib/set-object-value/src/index.jsnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-4jj4-m52p-8rx3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-28281ghsaADVISORY
- www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28281nvdBroken LinkThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.