VYPR
High severity7.3NVD Advisory· Published Jan 14, 2021· Updated Jun 17, 2026

CVE-2020-28470

CVE-2020-28470

Description

This affects the package @scullyio/scully before 1.0.9. The transfer state is serialised with the JSON.stringify() function and then written into the HTML page.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@scullyio/scullynpm
< 1.0.91.0.9
@scullyio/ng-libnpm
< 1.0.11.0.1

Affected products

4

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.