{"id":"GHSA-wfwq-xc57-fq7v","summary":"eivindfjeldstad-dot contains prototype pollution vulnerability","details":"eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.","aliases":["CVE-2020-7639","SNYK-JS-EIVIFJDOT-564435"],"modified":"2026-07-08T06:49:50.217188001Z","published":"2021-05-25T15:59:14Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-09-07T23:58:45Z","nvd_published_at":"2020-04-06T13:15:00Z","cwe_ids":["CWE-1321","CWE-915"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7639"},{"type":"WEB","url":"https://github.com/eivindfjeldstad/dot/commit/774e4b0c97ca35d2ae40df2cd14428d37dd07a0b"},{"type":"PACKAGE","url":"https://github.com/eivindfjeldstad/dot"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-EIVIFJDOT-564435"}],"affected":[{"package":{"name":"@eivifj/dot","ecosystem":"npm","purl":"pkg:npm/%40eivifj/dot"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/05/GHSA-wfwq-xc57-fq7v/GHSA-wfwq-xc57-fq7v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}