PT-2026-22065 · Dottie · Dottie

76Embiid21

·

Published

2023-06-10

·

Updated

2026-02-26

·

CVE-2026-27837

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions dottie versions 2.0.4 through 2.0.6
Description dottie is a JavaScript library for nested object access and manipulation. Versions 2.0.4 through 2.0.6 contain an incomplete fix for a prototype pollution issue. The prototype pollution guard only validates the first segment of a dot-separated path, allowing attackers to bypass the protection by placing proto at any position other than the first. The dottie.set() and dottie.transform() functions are affected. Versions prior to 2.0.4 are vulnerable due to insufficient checks within the set() function and the current variable in the /dottie.js file.
Recommendations Update to dottie version 2.0.7 or later.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2026-27837
GHSA-4GXF-G5GF-22H4
GHSA-R5MX-6WC6-7H9W

Affected Products

Dottie