High severity7.6NVD Advisory· Published Oct 20, 2020· Updated Jun 17, 2026
CVE-2020-7749
CVE-2020-7749
Description
This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as an HTML on the page which gives opportunity for XSS or rendered on the server (puppeteer) which also gives opportunity for SSRF and Local File Read.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
osm-static-mapsnpm | < 3.9.0 | 3.9.0 |
Affected products
3- cpe:2.3:a:osm-static-maps_project:osm-static-maps:*:*:*:*:*:node.js:*:*
- osm-static-maps/osm-static-mapsdescription
Patches
Vulnerability mechanics
References
6- github.com/jperelli/osm-static-maps/pull/24nvdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-OSMSTATICMAPS-609637nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-pxcf-v868-m492ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7749ghsaADVISORY
- github.com/jperelli/osm-static-maps/blob/master/src/template.html%23L142nvdBroken LinkWEB
- github.com/jperelli/osm-static-maps/commit/97355d29e08753d1cfe99b1281dbaa06f4e651b0ghsaWEB
News mentions
0No linked articles in our index yet.