CVE-2020-7708
CRITICALirrelon-path < 4.7.0 - Prototype Pollution via set, unSet, pushVal, and pullVal Functions
Title source: llmDescription
The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.
References (3)
Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-IRRELONPATH-598672
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-IRRELONPATH-598673
Patch, Third Party Advisory x_refsource_misc
https://github.com/Irrelon/irrelon-path/commit/8a126b160c1a854ae511659c111413ad9910ebe3
Scores
CVSS v3
9.8
EPSS
0.0282
EPSS Percentile
84.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-1321
Status
published
Products (4)
irrelon/\@irrelon\/path
< 4.7.0
irrelon/irrelon-path
< 4.7.0
irrelon/path
0 - 4.7.0npm
npm/irrelon-path
0 - 4.7.0npm
Published
Aug 18, 2020
Tracked Since
Feb 18, 2026