Executive brief
dset is a small utility used by developers to safely write values deep into JavaScript objects. A vulnerability in its merge mode allows an attacker to bypass security checks and modify the base structure of all objects in the application. This could lead to application crashes, unauthorized data modification, or potentially full control over the affected system.
Technical details
The dset library is vulnerable to prototype pollution when using the 'dset/merge' functionality. The root cause is an insufficient validation check that only inspects the top-level path for sensitive keys like '__proto__', 'constructor', or 'prototype'. An attacker can bypass this check by crafting a malicious object (e.g., using JSON.parse to include specific keys) that is then recursively merged into a target object. If successful, the attacker can pollute the global Object.prototype, which may lead to Denial of Service (DoS), property injection, or Remote Code Execution (RCE) depending on the application's environment. The issue is fixed in version 3.1.2.
Affected products
- lukeed dset < 3.1.2
Timeline
- 2022-01-06: disclosed
- 2022-03-23: advisory: Snyk advisory published
- 2022-05-01: advisory: NVD published CVE-2022-25645
- 2022-05-03: advisory: GitHub GHSA published