High severity7.5NVD Advisory· Published Nov 9, 2020· Updated Jun 17, 2026
CVE-2020-8268
CVE-2020-8268
Description
Prototype pollution vulnerability in json8-merge-patch npm package < 1.0.3 may allow attackers to inject or modify methods and properties of the global object constructor.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
json8-merge-patchnpm | < 1.0.3 | 1.0.3 |
Affected products
3- cpe:2.3:a:json8-merge-patch_project:json8-merge-patch:*:*:*:*:*:node.js:*:*Range: <1.0.3
- npm/json8-merge-patchdescription
Patches
Vulnerability mechanics
References
6- hackerone.com/reports/980649nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-8v9x-9xqg-r8mrghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-8268ghsaADVISORY
- github.com/sonnyp/JSON8/commit/2e890261b66cbc54ae01d0c79c71b0fd18379e7eghsaWEB
- github.com/sonnyp/JSON8/issues/113ghsaWEB
- www.npmjs.com/package/json8-merge-patchghsaWEB
News mentions
0No linked articles in our index yet.