High severity8.8NVD Advisory· Published Mar 15, 2020· Updated Jun 17, 2026
CVE-2020-8141
CVE-2020-8141
Description
The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
dotnpm | < 1.1.3 | 1.1.3 |
Affected products
3- cpe:2.3:a:dot_project:dot:1.1.2:*:*:*:*:node.js:*:*
Patches
Vulnerability mechanics
References
3- hackerone.com/reports/390929nvdExploitMitigationThird Party AdvisoryWEB
- github.com/advisories/GHSA-297x-8xj4-vcxvghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-8141ghsaADVISORY
News mentions
0No linked articles in our index yet.