CVE-2020-7660 is a high-severity remote code injection vulnerability affecting serialize-javascript versions prior to 3.1.0, specifically within the "deleteFunctions" function in "index.js". With a CVSS score of 8.1, this vulnerability allows unauthenticated remote attackers to execute arbitrary code with high impact on confidentiality, integrity, and availability, despite requiring high attack complexity. While the vulnerability has a relatively low EPSS score and is not on CISA's KEV list, it has garnered some community discussion and media coverage, though no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.1.0CPE matchmatch criteria | cpe:2.3:a:verizon:serialize-javascript:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.