{"id":"CVE-2020-7719","aliases":["GHSA-f98m-q3hr-p5wq","SNYK-JS-LOCUTUS-598675"],"url":"https://o3.security/vulnerability/CVE-2020-7719","summary":"Prototype Pollution in locutus","details":"Versions of package locutus before 2.0.12 are vulnerable to prototype Pollution via the php.strings.parse_str function.","published":"2020-09-01T10:15:10.560Z","modified":"2026-07-09T12:32:54.783244Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"npm","name":"locutus","fixedVersion":"2.0.12"}],"fix":{"url":"https://github.com/kvz/locutus/pull/418/","label":"kvz/locutus#418"},"references":[{"type":"EVIDENCE","url":"https://github.com/kvz/locutus/pull/418/"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-LOCUTUS-598675"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T12:32:54.783244Z"}}