High severity7.5NVD Advisory· Published Dec 15, 2020· Updated Jun 17, 2026
CVE-2020-28442
CVE-2020-28442
Description
All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
js-datanpm | < 3.0.10 | 3.0.10 |
Affected products
3- js-data/js-datadescription
Patches
Vulnerability mechanics
References
8- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1050978nvdExploitThird Party Advisory
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050979nvdExploitThird Party Advisory
- snyk.io/vuln/SNYK-JS-JSDATA-1023655nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-mqgv-67vx-g4m5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-28442ghsaADVISORY
- github.com/js-data/js-data/blob/master/src/utils.js%23L417nvdBroken Link
- github.com/js-data/js-data/commit/2d9eed5d3e9710d7e7fecc6f6437c39fe73a4097ghsaWEB
- github.com/js-data/js-data/pull/574ghsaWEB
News mentions
0No linked articles in our index yet.