Jison is a parser generator for JavaScript that translates grammar definitions into executable parsers; its vulnerability surface centers on the core Jison product and the code-generation mechanisms it employs. The recurring signal reflects OS command-injection weaknesses in the generator's handling of user-supplied grammar input, a structural concern for any tool that processes untrusted specifications and emits executable code. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jison Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-8178CRITICAL Insufficient input validation in npm package `jison` <= 0.4.18 may lead to OS command injection attacks. | Jul 15, 2020 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jison Project.
Media articles that mention a CVE ID that affects a product developed by Jison Project — matched by CVE ID, not by vendor name.