CVE-2020-7598
minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
- Published Mar 11, 2020
- CVSS 5.6 medium
- 1.9% chance of exploitation in the next 30 days (EPSS)
- Public exploit code is available
- A fix is available
Affected software
In the news
- Multiple vulnerabilities in IBM products CERT-FR ·