CVE-2020-7749
Status: ModifiedHigh (7.6)—
This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as an HTML on the page which gives opportunity for XSS or rendered on the server (puppeteer) which also gives opportunity for SSRF and Local File Read.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
- Base score: 7.6
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.60%
- Percentile among all scored CVEs: 75
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-74, CWE-79
References
- https://github.com/jperelli/osm-static-maps/blob/master/src/template.html%23L142
- https://github.com/jperelli/osm-static-maps/pull/24
- https://snyk.io/vuln/SNYK-JS-OSMSTATICMAPS-609637
- https://github.com/jperelli/osm-static-maps/blob/master/src/template.html%23L142
- https://github.com/jperelli/osm-static-maps/pull/24
- https://snyk.io/vuln/SNYK-JS-OSMSTATICMAPS-609637
Raw JSON (NVD)
Show
{
"id": "CVE-2020-7749",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
"authentication": "SINGLE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "report@snyk.io",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.6,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 4.7,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "report@snyk.io",
"affectedData": [
{
"vendor": "n/a",
"product": "osm-static-maps",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "unspecified",
"versionType": "custom"
}
]
}
]
}
],
"published": "2020-10-20T11:15:12.660",
"references": [
{
"url": "https://github.com/jperelli/osm-static-maps/blob/master/src/template.html%23L142",
"tags": [
"Broken Link"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/jperelli/osm-static-maps/pull/24",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://snyk.io/vuln/SNYK-JS-OSMSTATICMAPS-609637",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/jperelli/osm-static-maps/blob/master/src/template.html%23L142",
"tags": [
"Broken Link"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/jperelli/osm-static-maps/pull/24",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://snyk.io/vuln/SNYK-JS-OSMSTATICMAPS-609637",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-74"
},
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as an HTML on the page which gives opportunity for XSS or rendered on the server (puppeteer) which also gives opportunity for SSRF and Local File Read."
},
{
"lang": "es",
"value": "Esto afecta a todas las versiones del paquete osm-static-maps. Una entrada de usuario dada al paquete es pasada directamente a una plantilla sin escapar ({{{...}}}). Como tal, es posible que un atacante inyecte código HTML/JS arbitrario y dependiendo del contexto. Se generará como un HTML en la página que otorga la oportunidad de un XSS o se renderizaba en el servidor (puppeteer) que también otorga la oportunidad de un SSRF y una lectura de archivos locales"
}
],
"lastModified": "2026-06-17T03:25:22.653",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:osm-static-maps_project:osm-static-maps:*:*:*:*:*:node.js:*:*",
"vulnerable": true,
"matchCriteriaId": "02D6B0BB-1A95-4C5B-861B-598C32A63812"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "report@snyk.io"
}