{"id":"CVE-2020-7768","aliases":["GHSA-pp75-xfpw-37g9"],"url":"https://o3.security/vulnerability/CVE-2020-7768","summary":"Prototype pollution in grpc and @grpc/grpc-js","details":"\"The package grpc before 1.24.4 and the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition.\"","published":"2020-11-11T11:15:10.930Z","modified":"2026-08-07T15:14:47.516303Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"grpc","fixedVersion":"1.24.4"},{"ecosystem":"npm","name":"@grpc/grpc-js","fixedVersion":"1.1.8"}],"fix":{"url":"https://github.com/grpc/grpc-node/pull/1605","label":"grpc/grpc-node#1605"},"references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1038819"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-GRPC-598671"},{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-GRPCGRPCJS-1038818"},{"type":"FIX","url":"https://github.com/grpc/grpc-node/pull/1605"},{"type":"FIX","url":"https://github.com/grpc/grpc-node/pull/1606"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7768"},{"type":"WEB","url":"https://github.com/grpc/grpc-node/releases/tag/grpc%401.24.4"},{"type":"WEB","url":"https://www.npmjs.com/package/@grpc/grpc-js"},{"type":"WEB","url":"https://www.npmjs.com/package/grpc"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T15:14:47.516303Z"}}