216.73.216.233

CVE-2026-26021

· Published 11/02/2026 22:15 · Modified 11/02/2026 22:15

Labels: CVE-2026-26021 2026-02-11CVE-2026-26021CWE-1321[email protected]

Essential information

Published
11/02/2026 22:15
Modified
11/02/2026 22:15
Author
Creator
CVSS
9.4 CRITICAL (v3) 9.4 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (>=2.0.1, < 2.0.5). Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using Array.prototype. This has been fixed in version 2.0.5.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
set-in / set-in cpe:2.3:a:set-in:set-in:<2.0.5:*:*:*:*:*:*:*
set-in / set-in cpe:2.3:a:set-in:set-in:2.0.5:*:*:*:*:*:*:*

References