Medium severity6.5NVD Advisory· Published May 1, 2022· Updated Jun 17, 2026
CVE-2022-25645
CVE-2022-25645
Description
All versions of package dset are vulnerable to Prototype Pollution via 'dset/merge' mode, as the dset function checks for prototype pollution by validating if the top-level path contains __proto__, constructor or protorype. By crafting a malicious object, it is possible to bypass this check and achieve prototype pollution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dsetnpm | < 3.1.2 | 3.1.2 |
org.webjars.npm:dsetMaven | < 3.1.2 | 3.1.2 |
Affected products
4- cpe:2.3:a:dset_project:dset:*:*:*:*:*:node.js:*:*
- dset/dsetdescription
- ghsa-coords2 versions
< 3.1.2+ 1 more
- (no CPE)range: < 3.1.2
- (no CPE)range: < 3.1.2
Patches
Vulnerability mechanics
References
6- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2431974nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-DSET-2330881nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-23wx-cgxq-vpwxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25645ghsaADVISORY
- github.com/lukeed/dset/blob/master/src/merge.js%23L9nvdBroken LinkWEB
- github.com/lukeed/dset/pull/38nvd
News mentions
0No linked articles in our index yet.