{"id":"CVE-2020-7795","aliases":["GHSA-4h66-vghf-xg5x"],"url":"https://o3.security/vulnerability/CVE-2020-7795","summary":"get-npm-package-version Command Injection vulnerability","details":"The package get-npm-package-version before 1.0.7 is vulnerable to Command Injection via the `main` function in index.js.","published":"2022-08-02T14:15:09.953Z","modified":"2026-07-08T05:59:08.276905967Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"get-npm-package-version","fixedVersion":"1.0.7"}],"fix":{"url":"https://github.com/hoperyy/get-npm-package-version/commit/40b1cf31a0607ea66f9e30a0c3af1383b52b2dec","label":"hoperyy/get-npm-package-version@40b1cf3"},"references":[{"type":"WEB","url":"https://github.com/hoperyy/get-npm-package-version/blob/338a5882298eb2c2194538db41166cae13c39e03/index.js%23L17"},{"type":"ADVISORY","url":"https://www.npmjs.com/package/get-npm-package-version/v/1.0.6"},{"type":"FIX","url":"https://github.com/hoperyy/get-npm-package-version/commit/40b1cf31a0607ea66f9e30a0c3af1383b52b2dec"},{"type":"FIX","url":"https://security.snyk.io/vuln/SNYK-JS-GETNPMPACKAGEVERSION-1050390"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7795"},{"type":"WEB","url":"https://github.com/hoperyy/get-npm-package-version/commit/49459d4a3ce68587d48ffa8dead86fc9ed58e965"},{"type":"PACKAGE","url":"https://github.com/hoperyy/get-npm-package-version"},{"type":"WEB","url":"https://github.com/hoperyy/get-npm-package-version/blob/338a5882298eb2c2194538db41166cae13c39e03/index.js#L17"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:59:08.276905967Z"}}