Feed/CVE-2020-7623
CVE-2020-7623CRITICALCVSS 9.8

OS Command Injection in jscover

Published Feb 10, 2022·Updated Jul 6, 2026

NVD Description

jscover through 1.0.0 is vulnerable to Command Injection. It allows execution of arbitrary command via the source argument.

Affected Packages (1)

jscoverNPM
Fixed in = 1.0.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free