High severity7.8NVD Advisory· Published May 16, 2020· Updated Jun 17, 2026
CVE-2020-13110
CVE-2020-13110
Description
The kerberos package before 1.0.0 for Node.js allows arbitrary code execution and privilege escalation via injection of malicious DLLs through use of the kerberos_sspi LoadLibrary() method, because of a DLL path search.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
kerberosnpm | < 1.0.0 | 1.0.0 |
Affected products
3- Node.js/kerberos packagedescription
Patches
Vulnerability mechanics
References
8- www.op-c.net/2020/05/15/dll-injection-attack-in-kerberos-npm-package/nvdExploitMitigationThird Party Advisory
- github.com/advisories/GHSA-m2mx-rfpw-jghvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-13110ghsaADVISORY
- www.linkedin.com/posts/op-innovate_dll-injection-attack-in-kerberos-npm-package-activity-6667043749547253760-kVlWnvdThird Party AdvisoryWEB
- www.npmjs.com/advisories/1514nvdThird Party AdvisoryWEB
- medium.com/@kiddo_Ha3ker/dll-injection-attack-in-kerberos-npm-package-cb4b32031cdghsaWEB
- www.op-c.net/2020/05/15/dll-injection-attack-in-kerberos-npm-packageghsaWEB
- medium.com/%40kiddo_Ha3ker/dll-injection-attack-in-kerberos-npm-package-cb4b32031cdnvd
News mentions
0No linked articles in our index yet.