High severity7.5NVD Advisory· Published Mar 6, 2023· Updated Jun 17, 2026
CVE-2023-26106
CVE-2023-26106
Description
All versions of the package dot-lens are vulnerable to Prototype Pollution via the set() function in index.js file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dot-lensnpm | <= 1.2.3 | — |
Affected products
3- dot-lens/dot-lensdescription
Patches
Vulnerability mechanics
References
5- security.snyk.io/vuln/SNYK-JS-DOTLENS-3227646nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-rmhg-2cvv-q7vxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-26106ghsaADVISORY
- github.com/jb55/dot-lens/blob/465ef2088e4065b7be1c4372eedd2215c3820bc4/index.jsghsaWEB
- github.com/jb55/dot-lens/blob/465ef2088e4065b7be1c4372eedd2215c3820bc4/index.js%23L70nvdBroken Link
News mentions
0No linked articles in our index yet.