{"api_version":"1","generated_at":"2026-07-23T10:35:23+00:00","cve":"CVE-2020-7770","urls":{"html":"https://cve.report/CVE-2020-7770","api":"https://cve.report/api/cve/CVE-2020-7770.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-7770","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-7770"},"summary":{"title":"CVE-2020-7770","description":"This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.","state":"PUBLIC","assigner":"report@snyk.io","published_at":"2020-11-12 11:15:00","updated_at":"2022-12-02 19:44:00"},"problem_types":["CWE-1321"],"metrics":[],"references":[{"url":"https://github.com/sonnyp/JSON8/commit/2e890261b66cbc54ae01d0c79c71b0fd18379e7e","name":"https://github.com/sonnyp/JSON8/commit/2e890261b66cbc54ae01d0c79c71b0fd18379e7e","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"json8-merge-patch: Prevent prototype pollution 2 (#116) · sonnyp/JSON8@2e89026 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://snyk.io/vuln/SNYK-JS-JSON8-1017116","name":"https://snyk.io/vuln/SNYK-JS-JSON8-1017116","refsource":"MISC","tags":["Third Party Advisory"],"title":"Prototype Pollution in json8 | Snyk","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-7770","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7770","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"LEGACY","value":"Alessio Della Libera (d3lla)","lang":""}],"nvd_cpes":[{"cve_year":"2020","cve_id":"7770","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"json8_project","cpe5":"json8","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"7770","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"json8_project","cpe5":"json8","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-7770","qid":"982608","title":"Nodejs (npm) Security Update for json8 (GHSA-7h43-gx24-p529)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ASSIGNER":"report@snyk.io","DATE_PUBLIC":"2020-11-12T10:13:51.539284Z","ID":"CVE-2020-7770","STATE":"PUBLIC","TITLE":"Prototype Pollution"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"json8","version":{"version_data":[{"version_affected":"<","version_value":"1.0.3"}]}}]},"vendor_name":"n/a"}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Prototype Pollution"}]}]},"references":{"reference_data":[{"refsource":"MISC","url":"https://snyk.io/vuln/SNYK-JS-JSON8-1017116","name":"https://snyk.io/vuln/SNYK-JS-JSON8-1017116"},{"refsource":"MISC","url":"https://github.com/sonnyp/JSON8/commit/2e890261b66cbc54ae01d0c79c71b0fd18379e7e","name":"https://github.com/sonnyp/JSON8/commit/2e890261b66cbc54ae01d0c79c71b0fd18379e7e"}]},"description":{"description_data":[{"lang":"eng","value":"This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution."}]},"impact":{"cvss":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"}},"credit":[{"lang":"eng","value":"Alessio Della Libera (d3lla)"}]},"nvd":{"publishedDate":"2020-11-12 11:15:00","lastModifiedDate":"2022-12-02 19:44:00","problem_types":["CWE-1321"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:json8_project:json8:*:*:*:*:*:*:*:*","versionEndExcluding":"1.0.3","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"7770","Ordinal":"168051","Title":"CVE-2020-7770","CVE":"CVE-2020-7770","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"7770","Ordinal":"1","NoteData":"This affects the package json8 before 1.0.3. The function adds in the target object the property specified in the path, however it does not properly check the key being set, leading to a prototype pollution.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"7770","Ordinal":"2","NoteData":"2020-11-12","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"7770","Ordinal":"3","NoteData":"2020-11-12","Type":"Other","Title":"Modified"}]}}}