Critical severity9.8NVD Advisory· Published Jun 10, 2021· Updated Jun 17, 2026
CVE-2021-25949
CVE-2021-25949
Description
Prototype pollution vulnerability in 'set-getter' version 0.1.0 allows an attacker to cause a denial of service and may lead to remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
set-getternpm | < 0.1.1 | 0.1.1 |
Affected products
3- cpe:2.3:a:set-getter_project:set-getter:0.1.0:*:*:*:*:*:*:*
- set-getter/set-getterdescription
Patches
Vulnerability mechanics
References
6- github.com/doowb/set-getter/blob/5bc2750fe1c3db9651d936131be187744111378d/index.jsnvdExploitThird Party AdvisoryWEB
- www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25949nvdExploitThird Party Advisory
- github.com/advisories/GHSA-jv35-xqg7-f92rghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-25949ghsaADVISORY
- github.com/doowb/set-getter/commit/66eb3f0d4686a4a8c7c3d6f7ecd8e570b580edc4ghsaWEB
- web.archive.org/web/20210615022308/https://www.whitesourcesoftware.com/vulnerability-database/CVE-2021-25949ghsaWEB
News mentions
0No linked articles in our index yet.