Loading
This affects the package json before 10.0.0. It is possible to inject arbritary commands using the parseLookup function.
Cite this page
CVE-2020-7712. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2020-7712
Use CWE-78, Joyent vendor hub and Json product page to widen CVE-2020-7712 into its surrounding weakness, vendor, and product context.