Medium severity5.6NVD Advisory· Published Feb 16, 2021· Updated Jun 17, 2026
CVE-2021-20066
CVE-2021-20066
Description
JSDom improperly allows the loading of local resources, which allows for local files to be manipulated by a malicious web page when script execution is enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
jsdomnpm | < 16.5.0 | 16.5.0 |
Affected products
2- cpe:2.3:a:jsdom_project:jsdom:-:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
6- github.com/jsdom/jsdom/issues/3124nvdExploitIssue TrackingThird Party AdvisoryWEB
- www.tenable.com/security/research/tra-2021-05nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-f4c9-cqv8-9v98ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-20066ghsaADVISORY
- github.com/jsdom/jsdom/issues/3124ghsaWEB
- security.snyk.io/vuln/SNYK-JS-JSDOM-1075447ghsaWEB
News mentions
0No linked articles in our index yet.