PT-2026-22065 · Dottie · Dottie

76Embiid21

·

Publicado

2023-06-10

·

Atualizado

2026-02-26

·

CVE-2026-27837

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dottie versions 2.0.4 through 2.0.6
Description dottie is a JavaScript library for nested object access and manipulation. Versions 2.0.4 through 2.0.6 contain an incomplete fix for a prototype pollution issue. The prototype pollution guard only validates the first segment of a dot-separated path, allowing attackers to bypass the protection by placing proto at any position other than the first. The dottie.set() and dottie.transform() functions are affected. Versions prior to 2.0.4 are vulnerable due to insufficient checks within the set() function and the current variable in the /dottie.js file.
Recommendations Update to dottie version 2.0.7 or later.

Exploit

Correção

Prototype Pollution

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27837
GHSA-4GXF-G5GF-22H4
GHSA-R5MX-6WC6-7H9W

Produtos afetados

Dottie