Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-7677

31
FAUCET Score

CVE-2020-7677 is a critical vulnerability in the 'thenify' package, affecting versions prior to 3.3.1, as well as various Debian and Fedora distributions. It allows for remote code execution due to unsanitized user input being passed directly to an 'eval' function. With a CVSS score of 9.8, this vulnerability presents a severe risk, enabling unauthenticated attackers to achieve full compromise of affected systems with low attack complexity. Despite its critical severity, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.3.1CPE matchmatch criteria
cpe:2.3:a:thenify_project:thenify:*:*:*:*:*:node.js:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
36CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
37CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
LOW
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.97%
Probability of exploitation in next 30 days
EPSS Percentile
78.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0197 is in the 67th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: org.webjars.npm:thenifyFixed in: 3.3.1
npmpatch availablevia ghsa
Product: thenifyFixed in: 3.3.1
redhatno patchvia redhat_api
Product: OpenShift Service Mesh 2Fixed in: openshift-service-mesh/kiali-rhel8
redhatno patchvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: thenify
redhatno patchvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: openshift4/ose-console

Vendor Advisories (2)

redhatCVE-2020-7677Important

thenify: Arbitrary Code Execution in thenify

Jul 25, 2022
npmGHSA-29xr-v42j-r956critical

thenify before 3.3.1 made use of unsafe calls to `eval`.

Jul 18, 2022

References

github.com / thenables/thenify/blob/master/index.js%23L17
Broken Link
github.com / thenables/thenify/commit/0d94a24eb933bc835d568f3009f4d269c4c4c17a
Patch
lists.debian.org / debian-lts-announce/2022/09/msg00039.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/MTEUUTNIEBHGKUKKLNUZSV7IEP6IP3Q3
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/UM6XJ73Q3NAM5KSGCOKJ2ZIA6GUWUJLK
security.snyk.io / vuln/SNYK-JAVA-ORGWEBJARSNPM-572317
ExploitThird Party Advisory
security.snyk.io / vuln/SNYK-JS-THENIFY-571690
ExploitThird Party Advisory