Medium severity6.5NVD Advisory· Published Nov 12, 2020· Updated Jun 17, 2026
CVE-2020-7770
CVE-2020-7770
Description
This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
json8npm | < 1.0.3 | 1.0.3 |
Affected products
3- json8/json8description
Patches
Vulnerability mechanics
References
5- github.com/sonnyp/JSON8/commit/2e890261b66cbc54ae01d0c79c71b0fd18379e7envdPatchThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-JSON8-1017116nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-7h43-gx24-p529ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7770ghsaADVISORY
- www.npmjs.com/package/json8ghsaWEB
News mentions
0No linked articles in our index yet.