CVE-2020-7725 is a critical prototype pollution vulnerability affecting all versions of the worksmith package, allowing an unauthenticated attacker to remotely execute arbitrary code. With a CVSS score of 9.8, this flaw carries a high risk of complete compromise of confidentiality, integrity, and availability. While no public exploit code or active exploitation has been confirmed, the vulnerability has garnered significant community discussion, indicating potential interest from threat actors. Organizations using worksmith should prioritize patching to mitigate this severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:guidesmiths:worksmith:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.