High severity7.5NVD Advisory· Published Dec 11, 2020· Updated Jun 17, 2026
CVE-2020-7792
CVE-2020-7792
Description
This affects all versions of package mout. The deepFillIn function can be used to 'fill missing properties recursively', while the deepMixIn 'mixes objects into the target object, recursively mixing existing child objects as well'. In both cases, the key used to access the target object recursively is not checked, leading to a Prototype Pollution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
moutnpm | < 1.2.3 | 1.2.3 |
Affected products
2Patches
Vulnerability mechanics
References
8- github.com/mout/mout/blob/master/src/object/deepFillIn.jsnvdExploitThird Party AdvisoryWEB
- github.com/mout/mout/blob/master/src/object/deepMixIn.jsnvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1050374nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050373nvdExploitThird Party AdvisoryWEB
- snyk.io/vuln/SNYK-JS-MOUT-1014544nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-pc58-wgmc-hfjrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7792ghsaADVISORY
- github.com/mout/mout/commit/3fecf1333e6d71ae72edf48c71dc665e40df7605ghsaWEB
News mentions
0No linked articles in our index yet.