diff --git a/src/object/set.js b/src/object/set.js index b8fa25a3..a38f332e 100644 --- a/src/object/set.js +++ b/src/object/set.js @@ -4,6 +4,10 @@ define(['./namespace'], function (namespace) { * set "nested" object property */ function set(obj, prop, val){ + // prototype pollution mitigation + if(prop.includes('__proto__') || prop.includes('prototype') || prop.includes('constructor')) { + return false; + } var parts = (/^(.+)\.(.+)$/).exec(prop); if (parts){ namespace(obj, parts[1])[parts[2]] = val;