Thenify Project maintains a narrowly scoped promise-handling library with minimal tracked disclosures, making it a niche component in the broader JavaScript ecosystem. The limited characterization available centers on the core product itself, with observed issues documented under generic placeholder classifications rather than specific vulnerability mechanics. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thenify Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7677CRITICAL This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval funct | Jul 25, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thenify Project.
Media articles that mention a CVE ID that affects a product developed by Thenify Project — matched by CVE ID, not by vendor name.