Medium severity5.3NVD Advisory· Published Mar 12, 2020· Updated Jun 17, 2026
CVE-2020-7600
CVE-2020-7600
Description
querymen prior to 2.1.4 allows modification of object properties. The parameters of exported function handler(type, name, fn) can be controlled by users without any sanitization. This could be abused for Prototype Pollution attacks.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
querymennpm | < 2.1.4 | 2.1.4 |
Affected products
3- querymen/querymendescription
Patches
Vulnerability mechanics
References
4- snyk.io/vuln/SNYK-JS-QUERYMEN-559867nvdPatchThird Party AdvisoryWEB
- github.com/diegohaz/querymen/commit/1987fefcb3b7508253a29502a008d5063a873cefnvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-2cf2-2383-h4jvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7600ghsaADVISORY
News mentions
0No linked articles in our index yet.