High severity7.5NVD Advisory· Published Feb 4, 2022· Updated Jun 17, 2026
CVE-2021-23507
CVE-2021-23507
Description
The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-OBJECTPATHSET-607908
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
object-path-setnpm | < 1.0.2 | 1.0.2 |
Affected products
3- object-path-set/object-path-setdescription
Patches
Vulnerability mechanics
References
7- github.com/skratchdot/object-path-set/commit/2d67a714159c4099589b6661fa84e6d2adc31761nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-OBJECTPATHSET-2388576nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-h6pr-c536-6rjgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-23507ghsaADVISORY
- snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/nvdThird Party Advisory
- github.com/skratchdot/object-path-set/blob/577f5299fed15bb9edd11c940ff3cf0b9f4748d5/index.js%23L8nvdBroken LinkWEB
- snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validationghsaWEB
News mentions
0No linked articles in our index yet.