Vulnerability DatabaseGHSA-9qrg-h9g8-c65q

GHSA-9qrg-h9g8-c65q
JavaScript vulnerability analysis and mitigation

Overview

The deep-setter npm package has been identified with a high-severity prototype pollution vulnerability (GHSA-9qrg-h9g8-c65q). This security issue affects all versions of the package (>= 0.0.0) and was initially discovered and reviewed on August 31, 2020, with publication to the GitHub Advisory Database following on September 4, 2020. The vulnerability remains active with no patched versions available as of the last update on January 9, 2023 (GitHub Advisory).

Technical details

The vulnerability is classified under CWE-1321 and has been assessed as high severity. The core issue lies in the package's failure to implement restrictions on Object prototype modifications, which creates a security weakness in the application's object handling mechanisms (GitHub Advisory).

Impact

When exploited, this vulnerability allows attackers to modify or add properties to an Object's prototype, which subsequently affects all objects in the application. This can lead to significant security implications as these modifications will exist across all objects in the application's scope (GitHub Advisory).

Exploitability

The vulnerability is present in all versions of the deep-setter package, making it widely exploitable in any application using this dependency. No specific exploit details have been publicly disclosed, but the fundamental nature of prototype pollution makes this a significant security concern (GitHub Advisory).

Mitigation and workarounds

Currently, no official fix or patch is available for this vulnerability. The recommended mitigation strategy is to consider using alternative packages until a security fix is made available (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54155HIGH7.7
  • JavaScript logoJavaScript
  • node-opcua
NoNoAug 20, 2026
CVE-2026-54156HIGH7.5
  • JavaScript logoJavaScript
  • node-opcua
NoYesAug 20, 2026
CVE-2026-55451MEDIUM6.9
  • JavaScript logoJavaScript
  • gettext-converter
NoYesAug 20, 2026
CVE-2026-54150MEDIUM6.9
  • JavaScript logoJavaScript
  • next-video
NoYesAug 20, 2026
GHSA-ghvf-qf6h-g8x5HIGHN/A
  • JavaScript logoJavaScript
  • @nocobase/server
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management