{"id":"CVE-2020-7598","title":"minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a \"constructor\" or \"__proto__\" payload.","summary":"minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a \"constructor\" or \"__proto__\" payload.","severity":"medium","cvss":5.6,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-1321"],"vendor":"substack","product":"minimist","affected":["minimist < 1.2.2","leap = 15.1"],"patched":["minimist 1.2.2"],"published":"2020-03-11","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:30.997","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-7598","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html","label":"report@snyk.io"},{"url":"https://snyk.io/vuln/SNYK-JS-MINIMIST-559764","label":"report@snyk.io"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://snyk.io/vuln/SNYK-JS-MINIMIST-559764","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.01931,"epssPercentile":0.7939,"exploits":{"github":1,"githubRepos":["https://github.com/renewablehacking/CVE-2020-7598"],"checkedAt":"2026-10-08T22:12:29.990Z"},"exploitAvailable":true,"ingestedAt":"2026-10-08T22:11:53.711Z","slug":"CVE-2020-7598","body":"## Overview\n\nminimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a \"constructor\" or \"__proto__\" payload.\n\n## Affected\n\n- `minimist < 1.2.2`\n- `leap = 15.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `minimist 1.2.2`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":30.8,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[]}