Codecov provides code coverage analysis and reporting services integrated into development pipelines, with exposure centered on its primary platform and language-specific uploaders such as the Python and Node.js variants. The durable signal across its disclosures reflects command-injection and argument-injection weaknesses in credential handling and shell-command composition, which are endemic to tools that must interact with build systems and shell environments. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Codecov over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15123CRITICAL In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikely to be aware of this, so they | Jul 20, 2020 | 9.3 | 31 | NO | NO |
CVE-2020-7596HIGH Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument. | Jan 25, 2020 | 8.8 | 27 | NO | NO |
CVE-2020-7597HIGH codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is executed by the exec function wit | Feb 17, 2020 | 8.8 | 25 | NO | NO |
CVE-2019-10800MEDIUM This affects the package codecov before 2.0.16. The vulnerability occurs due to not sanitizing gcov arguments before being being provided to the popen method. | Jul 13, 2022 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Codecov.
Media articles that mention a CVE ID that affects a product developed by Codecov — matched by CVE ID, not by vendor name.