Medium severity5.6NVD Advisory· Published Oct 20, 2020· Updated Jun 17, 2026
CVE-2020-7748
CVE-2020-7748
Description
This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@tsed/corenpm | < 5.65.7 | 5.65.7 |
Affected products
3- @tsed/core/@tsed/coredescription
Patches
Vulnerability mechanics
References
5- github.com/TypedProject/tsed/blob/production/packages/core/src/utils/deepExtends.ts%23L36nvdBroken LinkPatchThird Party AdvisoryWEB
- github.com/TypedProject/tsed/commit/1395773ddac35926cf058fc6da9fb8e82266761bnvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-TSEDCORE-1019382nvdExploitPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-77xq-cpvg-7xm2ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7748ghsaADVISORY
News mentions
0No linked articles in our index yet.