{"id":"CVE-2022-25862","aliases":[],"url":"https://o3.security/vulnerability/CVE-2022-25862","summary":"This affects the package sds from 0.0.0. The library could be tricked into adding or modifying properties of the Object.prototype by abusing the set function located in js/set.js. **Note:**…","details":"This affects the package sds from 0.0.0. The library could be tricked into adding or modifying properties of the Object.prototype by abusing the set function located in js/set.js. **Note:** This vulnerability derives from an incomplete fix to [CVE-2020-7618](https://security.snyk.io/vuln/SNYK-JS-SDS-564123)","published":"2022-05-13T20:15:08.187","modified":"2026-06-17T04:34:24.477","cvss":{"score":4,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/monsterkodi/sds/blob/master/js/set.js"},{"type":"EXPLOIT","url":"https://snyk.io/vuln/SNYK-JS-SDS-2385944"},{"type":"ADVISORY","url":"https://github.com/monsterkodi/sds/blob/master/js/set.js"},{"type":"EXPLOIT","url":"https://snyk.io/vuln/SNYK-JS-SDS-2385944"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T04:34:24.477"}}