High severity8.8NVD Advisory· Published Jan 25, 2020· Updated Jun 17, 2026
CVE-2020-7596
CVE-2020-7596
Description
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
codecovnpm | < 3.6.2 | 3.6.2 |
Affected products
3- Codecov/npm moduledescription
Patches
Vulnerability mechanics
References
3- snyk.io/vuln/SNYK-JS-CODECOV-543183nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-mh2h-6j8q-x246ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7596ghsaADVISORY
News mentions
0No linked articles in our index yet.