{"id":"CVE-2020-7639","aliases":["GHSA-wfwq-xc57-fq7v","SNYK-JS-EIVIFJDOT-564435"],"url":"https://o3.security/vulnerability/CVE-2020-7639","summary":"eivindfjeldstad-dot contains prototype pollution vulnerability","details":"eivindfjeldstad-dot below 1.0.3 is vulnerable to Prototype Pollution.The function 'set' could be tricked into adding or modifying properties of 'Object.prototype' using a '__proto__' payload.","published":"2020-04-06T13:15:12.987Z","modified":"2026-07-09T12:33:23.082774Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"@eivifj/dot","fixedVersion":"1.0.3"}],"fix":{"url":"https://github.com/eivindfjeldstad/dot/commit/774e4b0c97ca35d2ae40df2cd14428d37dd07a0b","label":"eivindfjeldstad/dot@774e4b0"},"references":[{"type":"FIX","url":"https://github.com/eivindfjeldstad/dot/commit/774e4b0c97ca35d2ae40df2cd14428d37dd07a0b"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-EIVIFJDOT-564435"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T12:33:23.082774Z"}}