Critical severity9.8NVD Advisory· Published Jun 4, 2018· Updated Jun 17, 2026
CVE-2017-16020
CVE-2017-16020
Description
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
summitnpm | >= 0.1.0, <= 0.1.22 | — |
Affected products
3- Range: >=0.1.0
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-cwcp-6c48-fm7mghsaADVISORY
- github.com/notduncansmith/summit/issues/23nvdThird Party AdvisoryWEB
- nodesecurity.io/advisories/315nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2017-16020ghsaADVISORY
News mentions
0No linked articles in our index yet.