Summit Project maintains a narrowly scoped project centered on the Summit product, where the observed vulnerability pattern centers on code-injection weaknesses arising from improper control of code generation. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Summit Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-16020CRITICAL Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name. | Jun 4, 2018 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Summit Project.
Media articles that mention a CVE ID that affects a product developed by Summit Project — matched by CVE ID, not by vendor name.