{"id":"CVE-2026-26021","summary":"Prototype pollution in set-in","details":"set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (\u003e=2.0.1, \u003c 2.0.5). Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using Array.prototype. This has been fixed in version 2.0.5.","aliases":["GHSA-2c4m-g7rx-63q7"],"modified":"2026-08-12T03:51:37.218285153Z","published":"2026-02-11T21:18:50.084Z","database_specific":{"cwe_ids":["CWE-1321"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26021.json","cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/26xxx/CVE-2026-26021.json"},{"type":"ADVISORY","url":"https://github.com/ahdinosaur/set-in/security/advisories/GHSA-2c4m-g7rx-63q7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-26021"},{"type":"FIX","url":"https://github.com/ahdinosaur/set-in/commit/b8e1dabfdbd35c8d604b6324e01d03f280256c3d"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/ahdinosaur/set-in","events":[{"introduced":"46c9d5463dcdfbf6f137fa2b4baae237d6c71b63"},{"fixed":"80caa1497afed18defd7025f41a01aa5503a7e48"},{"fixed":"b8e1dabfdbd35c8d604b6324e01d03f280256c3d"}],"database_specific":{"extracted_events":[{"introduced":"2.0.1"},{"fixed":"2.0.5"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:set-in_project:set-in:*:*:*:*:*:*:*:*"}}],"versions":["v2.0.4","v2.0.3","v2.0.2","v2.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-26021.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}