CVE-2026-26021Disclosure(set-in_project / set-in)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch set-in_project set-in systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (>=2.0.1, < 2.0.5). Despite a previous fix that attempted to mitigate prototype pollution by checking whether user input contained a forbidden key, it is still possible to pollute Object.prototype via a crafted input using Array.prototype. This has been fixed in version 2.0.5.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • set-in

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-02-12); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Products
set-in

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-02-11: 1Mentions · 2026-02-12: 2Mentions · 2026-02-13: 1Mentions · 2026-02-15: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 1Technical Details · 2026-02-15: 102-1102-1202-1302-15
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-111
Disclosure1
2026-02-122
Disclosure1Patch1
2026-02-131
Disclosure1
2026-02-151
Disclosure1
Full discourse5 posts
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-26021: Prototype pollution in set-in (C... Bypass of Array.prototype check in set-in enables prototype pollution even after previous mitigation - attackers can st... https://zerodaysignal.com/vulnerability/CVE-2026-26021 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A tweet announces CVE‑2026‑26021, noting it is a prototype‑pollution flaw in the set‑in library that bypasses a prior Array.prototype check, and links to a ZeroDaySignal page for more information.

    0001076
    131 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-26021 - Critical set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (&gt;=2.0.1, &amp;lt; 2.0.5). Despite ... https://www.thehackerwire.com/vulnerability/CVE-2026-26021/ https://t.co/NnVHtEAjnp

    Post summary

    The text announces a prototype pollution flaw in the npm package set-in (v2.0.1–2.0.4), labeled CVE-2026-26021.

    0000065
    112 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A prototype pollution vulnerability (CVE-2026-26021) affects the `set-in` library. This can lead to object manipulation or service disruption. Update to 2.0.5. #infosec #javascript #security https://www.pulsepatch.io/posts/cve-2026-26021-set-in-prototype-pollution

    Post summary

    The CVE‑2026‑26021 prototype‑pollution vulnerability in the set‑in library is mitigated by updating to version 2.0.5, with no evidence of a PoC, exploit, or active exploitation reported.

    0000037
    1 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-26021: The Ouroboros Bug: How set-in's Security Check Ate Itself A critical prototype pollution vulnerability in the `set-in` npm package exposes a fundamental misunderstanding of JavaScript's mutable environment. The library attempted to bla... https://cvereports.com/reports/CVE-2026-26021

    Post summary

    The article announces a critical prototype pollution vulnerability (CVE‑2026‑26021) in the set‑in npm package, describing the issue without providing PoC, exploit code, or remediation details.

    0000034
    27 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26021 set-in provides the set value of nested associative structure given array of keys. A prototype pollution vulnerability exists in the the npm package set-in (&gt;=2.0.1, … https://www.cve.org/CVERecord?id=CVE-2026-26021

    Post summary

    The text announces CVE‑2026‑26021, noting a prototype‑pollution flaw in the npm package set‑in (>=2.0.1), but does not mention exploitation, patches, or a proof of concept.

    00000168
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appset-in_projectset-in---

Explore more