High severity8.3NVD Advisory· Published Oct 2, 2020· Updated Jun 17, 2026
CVE-2020-7738
CVE-2020-7738
Description
All versions of package shiba are vulnerable to Arbitrary Code Execution due to the default usage of the function load() of the package js-yaml instead of its secure replacement , safeLoad().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
shibanpm | <= 1.2.1 | — |
Affected products
3- shiba/shibadescription
- cpe:2.3:a:shiba_project:shiba:*:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-jvf4-g24p-2qgwghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7738ghsaADVISORY
- snyk.io/vuln/SNYK-JS-SHIBA-596466nvdThird Party AdvisoryWEB
- www.npmjs.com/package/shibaghsaWEB
News mentions
0No linked articles in our index yet.