CVE-2020-7678
Estado: ModificadaCrítica (9.8)—
This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.13%
- Percentil entre todas las CVEs puntuadas: 65
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-noinfo
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-7678",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "report@snyk.io",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 8.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.7,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "report@snyk.io",
"affectedData": [
{
"vendor": "n/a",
"product": "node-import",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "unspecified",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-07-25T14:15:10.100",
"references": [
{
"url": "https://github.com/mahdaen/node-import/blob/master/index.js%23L79",
"tags": [
"Broken Link",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://security.snyk.io/vuln/SNYK-JS-NODEIMPORT-571691",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/mahdaen/node-import/blob/master/index.js%23L79",
"tags": [
"Broken Link",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.snyk.io/vuln/SNYK-JS-NODEIMPORT-571691",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "This affects all versions of package node-import. The \"params\" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file \"index.js\"."
},
{
"lang": "es",
"value": "Esto afecta a todas las versiones del paquete node-import. El argumento \"params\" de la función del módulo puede ser controlado por usuarios sin ningún tipo de saneo.b. Esto es luego proporcionado a la función \"eval\" ubicada en la línea 79 en el archivo index \"index.js\""
}
],
"lastModified": "2026-06-17T03:25:14.990",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:node-import_project:node-import:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "1A49E0B5-20B2-4588-9BFD-0D44F4F8799F"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "report@snyk.io"
}