CVE-2020-7722 describes a critical Prototype Pollution vulnerability (CVSS 9.8) affecting all versions of the nodee-utils package. This flaw, specifically within the deepSet function, allows an unauthenticated attacker to remotely execute arbitrary code, compromise data integrity, or cause denial of service. Despite its high severity and potential for complete system compromise, there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:nodee-utils_project:nodee-utils:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.