VYPR
Medium severity6.5NVD Advisory· Published Nov 12, 2020· Updated Jun 17, 2026

CVE-2020-7770

CVE-2020-7770

Description

This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
json8npm
< 1.0.31.0.3

Affected products

3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.