Critical severity9.8OSV Advisory· Published Aug 18, 2020· Updated Jun 17, 2026
CVE-2020-7708
CVE-2020-7708
Description
The package irrelon-path before 4.7.0; the package @irrelon/path before 4.7.0 are vulnerable to Prototype Pollution via the set, unSet, pushVal and pullVal functions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
irrelon-pathnpm | < 4.7.0 | 4.7.0 |
@irrelon/pathnpm | < 4.7.0 | 4.7.0 |
Affected products
5(expand)+ 1 more
- (no CPE)
- cpe:2.3:a:irrelon:irrelon-path:*:*:*:*:*:node.js:*:*range: <4.7.0
- ghsa-coords2 versions
< 4.7.0+ 1 more
- (no CPE)range: < 4.7.0
- (no CPE)range: < 4.7.0
Patches
Vulnerability mechanics
References
5- github.com/Irrelon/irrelon-path/commit/8a126b160c1a854ae511659c111413ad9910ebe3nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-IRRELONPATH-598672nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-IRRELONPATH-598673nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-j7cg-h9v9-6vqpghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7708ghsaADVISORY
News mentions
0No linked articles in our index yet.