The Ini Project maintains a configuration-parsing library that, despite a narrow scope, serves foundational roles across web frameworks and Node.js applications. Its documented vulnerability pattern centers on prototype pollution—improper handling of object attribute assignment during INI file parsing—a class of flaw that can propagate privilege or state across application contexts. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ini Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7788CRITICAL This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the appli | Dec 11, 2020 | 9.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ini Project.
Media articles that mention a CVE ID that affects a product developed by Ini Project — matched by CVE ID, not by vendor name.