← Back to browse · API

CVE-2020-7720

Severity
CRITICAL
CVSS
9.8
EPSS
0.03188
Risk score
40.32
CISA KEV
No
PoC
No
Published
2020-09-01
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2020-0922, GHSA-92XJ-MQP7-VMCJ
Products
Digital Bazaar:node-forge 0 <unspecified
Sources
euvd EUVD-2020-0922

Description

The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.

References