Critical severity9.8NVD Advisory· Published May 2, 2020· Updated Jun 17, 2026
CVE-2020-7645
CVE-2020-7645
Description
All versions of chrome-launcher allow execution of arbitrary commands, by controlling the $HOME environment variable in Linux operating systems.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
chrome-launchernpm | < 0.13.2 | 0.13.2 |
Affected products
3- chrome-launcher/chrome-launcherdescription
Patches
Vulnerability mechanics
References
4- snyk.io/vuln/SNYK-JS-CHROMELAUNCHER-537575nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-gp2j-mg4w-2rh5ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7645ghsaADVISORY
- github.com/GoogleChrome/chrome-launcher/pull/197ghsaWEB
News mentions
0No linked articles in our index yet.