Hunter Wodzenski

2 exploits Active since Sep 2020
CVE-2020-7720 WRITEUP CRITICAL WRITEUP
Digitalbazaar Forge < 0.10.0 - Prototype Pollution
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
CVSS 9.8
CVE-2025-12816 WRITEUP HIGH WRITEUP
node-forge <1.3.1 - SSRF
An interpretation-conflict (CWE-436) vulnerability in node-forge versions 1.3.1 and earlier enables unauthenticated attackers to craft ASN.1 structures to desynchronize schema validations, yielding a semantic divergence that may bypass downstream cryptographic verifications and security decisions.
CVSS 8.6