Critical severity9.8OSV Advisory· Published Nov 12, 2020· Updated Jun 17, 2026
CVE-2020-28270
CVE-2020-28270
Description
Prototype pollution vulnerability in 'object-hierarchy-access' versions 0.2.0 through 0.32.0 allows attacker to cause a denial of service and may lead to remote code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
object-hierarchy-accessnpm | >= 0.2.0, < 0.33.0 | 0.33.0 |
Affected products
3v0.10.0, v0.11.0, v0.12.0, …+ 1 more
- (no CPE)range: v0.10.0, v0.11.0, v0.12.0, …
- cpe:2.3:a:mjpclab:object-hierarchy-access:*:*:*:*:*:*:*:*range: >=0.2.0,<=0.32.0
Patches
Vulnerability mechanics
References
5- github.com/mjpclab/object-hierarchy-access/commit/7b1aa134a8bc4a376296bcfac5c3463aef2b7572nvdPatchThird Party AdvisoryWEB
- www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28270nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-fxwf-45c7-4pprghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-28270ghsaADVISORY
- www.whitesourcesoftware.com/vulnerability-database/CVE-2020-28270,ghsaWEB
News mentions
0No linked articles in our index yet.