Medium severity5.4OSV Advisory· Published Apr 22, 2020· Updated Jun 17, 2026
CVE-2020-7642
CVE-2020-7642
Description
lazysizes through 5.2.0 allows execution of malicious JavaScript. The following attributes are not sanitized by the video-embed plugin: data-vimeo, data-vimeoparams, data-youtube and data-ytparams which can be abused to inject malicious JavaScript.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
lazysizesnpm | < 5.2.1 | 5.2.1 |
Affected products
3Patches
Vulnerability mechanics
References
4- github.com/aFarkas/lazysizes/commit/3720ab8262552d4e063a38d8492f9490a231fd48nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-LAZYSIZES-567144nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-hg2p-2cvq-4ppvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7642ghsaADVISORY
News mentions
0No linked articles in our index yet.