Critical severity9.8NVD Advisory· Published Apr 2, 2020· Updated Jun 17, 2026
CVE-2020-7620
CVE-2020-7620
Description
pomelo-monitor through 0.3.7 is vulnerable to Command Injection.It allows injection of arbitrary commands as part of 'pomelo-monitor' params.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pomelo-monitornpm | <= 0.3.7 | — |
Affected products
3- pomelo-monitor/pomelo-monitordescription
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-4j54-mxf6-wxx2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7620ghsaADVISORY
- snyk.io/vuln/SNYK-JS-POMELOMONITOR-173695nvdThird Party AdvisoryWEB
- github.com/halfblood369/monitor/blob/900b5cadf59edcccac4754e5706a22719925ddb9/lib/processMonitor.js,ghsaWEB
- github.com/halfblood369/monitor/blob/900b5cadf59edcccac4754e5706a22719925ddb9/lib/processMonitor.js%2Cnvd
News mentions
0No linked articles in our index yet.