VYPR

Corenlp Js Interface

by npm

CVEs (2)

  • CVE-2020-28439Dec 11, 2020
    risk 0.00cvss epss 0.01

    This affects all versions of package corenlp-js-prefab. The injection point is located in line 10 in 'index.js.' It depends on a vulnerable package 'corenlp-js-interface.' Vulnerability can be exploited with the following PoC:

  • CVE-2020-28440Dec 11, 2020
    risk 0.00cvss epss 0.04

    All versions of package corenlp-js-interface are vulnerable to Command Injection via the main function.