Medium severity4.0NVD Advisory· Published May 13, 2022· Updated Jun 17, 2026
CVE-2022-25862
CVE-2022-25862
Description
This affects the package sds from 0.0.0. The library could be tricked into adding or modifying properties of the Object.prototype by abusing the set function located in js/set.js. Note: This vulnerability derives from an incomplete fix to CVE-2020-7618
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
sdsnpm | <= 4.4.0 | — |
Affected products
2- cpe:2.3:a:sds_project:sds:*:*:*:*:*:node.js:*:*
Patches
Vulnerability mechanics
References
5- snyk.io/vuln/SNYK-JS-SDS-2385944nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-ph28-wwfj-fv7fghsaADVISORY
- github.com/monsterkodi/sds/blob/master/js/set.jsnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-7618ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2022-25862ghsaADVISORY
News mentions
0No linked articles in our index yet.