PT-2026-22065 · Dottie · Dottie
76Embiid21
·
Published
2023-06-10
·
Updated
2026-02-26
·
CVE-2026-27837
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
dottie versions 2.0.4 through 2.0.6
Description
dottie is a JavaScript library for nested object access and manipulation. Versions 2.0.4 through 2.0.6 contain an incomplete fix for a prototype pollution issue. The prototype pollution guard only validates the first segment of a dot-separated path, allowing attackers to bypass the protection by placing
proto at any position other than the first. The dottie.set() and dottie.transform() functions are affected. Versions prior to 2.0.4 are vulnerable due to insufficient checks within the set() function and the current variable in the /dottie.js file.Recommendations
Update to dottie version 2.0.7 or later.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dottie