VYPR
High severity7.5NVD Advisory· Published Jul 20, 2020· Updated Jun 17, 2026

CVE-2020-8205

CVE-2020-8205

Description

The uppy npm package < 1.13.2 and < 2.0.0-alpha.5 is vulnerable to a Server-Side Request Forgery (SSRF) vulnerability, which allows an attacker to scan local or external networks or otherwise interact with internal systems.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@uppy/companionnpm
< 1.13.21.13.2
@uppy/companionnpm
>= 2.0.0-alpha.0, < 2.0.0-alpha.52.0.0-alpha.5

Affected products

8
  • Transloadit/Uppy7 versions
    cpe:2.3:a:transloadit:uppy:*:*:*:*:*:node.js:*:*+ 6 more
    • cpe:2.3:a:transloadit:uppy:*:*:*:*:*:node.js:*:*range: <1.13.2
    • cpe:2.3:a:transloadit:uppy:2.0.0:alpha0:*:*:*:node.js:*:*
    • cpe:2.3:a:transloadit:uppy:2.0.0:alpha1:*:*:*:node.js:*:*
    • cpe:2.3:a:transloadit:uppy:2.0.0:alpha2:*:*:*:node.js:*:*
    • cpe:2.3:a:transloadit:uppy:2.0.0:alpha3:*:*:*:node.js:*:*
    • cpe:2.3:a:transloadit:uppy:2.0.0:alpha4:*:*:*:node.js:*:*
    • (no CPE)range: Fixed Versions: 1.13.2, 2.0.0-alpha.5
  • ghsa-coords
    Range: < 1.13.2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.