CVE-2020-7708

CRITICAL

irrelon-path < 4.7.0 - Prototype Pollution via set, unSet, pushVal, and pullVal Functions

Title source: llm
STIX 2.1

Description

The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-IRRELONPATH-598672
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-IRRELONPATH-598673

Scores

CVSS v3 9.8
EPSS 0.0282
EPSS Percentile 84.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-1321
Status published
Products (4)
irrelon/\@irrelon\/path < 4.7.0
irrelon/irrelon-path < 4.7.0
irrelon/path 0 - 4.7.0npm
npm/irrelon-path 0 - 4.7.0npm
Published Aug 18, 2020
Tracked Since Feb 18, 2026