High severity7.5NVD Advisory· Published Feb 4, 2022· Updated Jun 17, 2026
CVE-2021-23497
CVE-2021-23497
Description
This affects the package @strikeentco/set before 1.0.2. It allows an attacker to cause a denial of service and may lead to remote code execution. Note: This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@strikeentco/setnpm | < 1.0.2 | 1.0.2 |
Affected products
3- @strikeentco/set/@strikeentco/setdescription
Patches
Vulnerability mechanics
References
7- github.com/strikeentco/set/commit/b2f942cnvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-2385945nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-39qv-prmh-x37fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23497ghsaADVISORY
- security.snyk.io/vuln/SNYK-JS-STRIKEENTCOSET-1038821ghsaWEB
- snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validationghsaWEB
- snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/nvdNot Applicable
News mentions
0No linked articles in our index yet.