CVE-2020-28495

HIGH

total.js < 3.4.7 - Prototype Pollution via Path Key Sanitization Bypass

Title source: llm
STIX 2.1

Description

This affects the package total.js before 3.4.7. The set function can be used to set a value into the object according to the path. However the keys of the path being set are not properly sanitized, leading to a prototype pollution vulnerability. The impact depends on the application. In some cases it is possible to achieve Denial of service (DoS), Remote Code Execution or Property Injection.

Scores

CVSS v3 7.3
EPSS 0.0609
EPSS Percentile 91.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

Details

Status published
Products (2)
npm/total.js 0 - 3.4.7npm
totaljs/total.js < 3.4.7
Published Feb 02, 2021
Tracked Since Feb 18, 2026