Critical severity9.8NVD Advisory· Published Apr 27, 2020· Updated Jun 17, 2026
CVE-2020-7640
CVE-2020-7640
Description
pixl-class prior to 1.0.3 allows execution of arbitrary commands. The members argument of the create function can be controlled by users without any sanitization.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pixl-classnpm | < 1.0.3 | 1.0.3 |
Affected products
3- pixl-class/pixl-classdescription
Patches
Vulnerability mechanics
References
6- github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-PIXLCLASS-564968nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-vm5j-vqr6-v7v8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7640ghsaADVISORY
- github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8,ghsaWEB
- github.com/jhuckaby/pixl-class/commit/47677a3638e3583e42f3a05cc7f0b30293d2acc8%2Cnvd
News mentions
0No linked articles in our index yet.