VYPR
High severity8.8NVD Advisory· Published Feb 17, 2020· Updated Jun 17, 2026

CVE-2020-7597

CVE-2020-7597

Description

codecov-node npm module before 3.6.5 allows remote attackers to execute arbitrary commands.The value provided as part of the gcov-root argument is executed by the exec function within lib/codecov.js. This vulnerability exists due to an incomplete fix of CVE-2020-7596.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
codecovnpm
< 3.6.53.6.5

Affected products

3
  • codecov-node/codecov-nodedescription
  • ghsa-coords
    Range: < 3.6.5
  • cpe:2.3:a:codecov:codecov:*:*:*:*:*:node.js:*:*
    Range: <3.6.5

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.