← Back to browse · API

CVE-2020-7782

Severity
CRITICAL
CVSS
9.8
EPSS
0.02472
Risk score
40.07
CISA KEV
No
PoC
No
Published
2021-02-08
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-0741, GHSA-333X-QR3V-G4XX
Products
n/a:spritesheet-js 0 <unspecified
Sources
euvd EUVD-2021-0741

Description

This affects all versions of package spritesheet-js. It depends on a vulnerable package platform-command. The injection point is located in line 32 in lib/generator.js, which is triggered by main entry of the package.

References