High severity8.6NVD Advisory· Published Mar 17, 2022· Updated Jun 17, 2026
CVE-2022-25354
CVE-2022-25354
Description
The package set-in before 2.0.3 are vulnerable to Prototype Pollution via the setIn method, as it allows an attacker to merge object prototypes into it. Note: This vulnerability derives from an incomplete fix of CVE-2020-28273
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
set-innpm | < 2.0.3 | 2.0.3 |
Affected products
3- set-in/set-indescription
Patches
Vulnerability mechanics
References
5- github.com/ahdinosaur/set-in/commit/6bad255961d379e4b1f5fbc52ef9dc8420816f24nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-SETIN-2388571nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-6956-83fg-5wc5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25354ghsaADVISORY
- github.com/ahdinosaur/set-in/blob/dfc226d95cce8129de6708661e06e0c2c06f3490/index.js%23L5nvdBroken LinkWEB
News mentions
0No linked articles in our index yet.