← Back

CVE-2020-7748

nvd nist
Published: Oct 20, 2020Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.

Affected (1)

Products: Ts.ed Project: Ts.ed
1 product
Ts.ed
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.65.7

References (6)

Source: report@snyk.io
ExploitPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Broken LinkPatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitPatchThird Party Advisory

Timeline

No history available yet.