@rvf/set-get has a prototype pollution issue that's reachable via @rvf/core preprocessFormData (HTTP form data) (CVE-2026-44483) | HOL Guard CVE