---
id: CVE-2020-7788
title: This affects the package ini before 1.3.6
summary: >-
  This affects the package ini before 1.3.6. If an attacker submits a malicious
  INI file to an application that parses it with ini.parse, they will pollute
  the prototype on the application. This can be exploited further depending on
  the co…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-1321
  - CWE-400
vendor: ini_project
product: ini
affected:
  - ini < 1.3.6
  - debian_linux = 9.0
patched:
  - ini 1.3.6
published: '2020-12-11'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:03.403'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2020-7788'
references:
  - url: 'https://github.com/npm/ini/commit/56d2805e07ccd94e2ba0984ac9240ff02d44b6f1'
    label: report@snyk.io
  - url: 'https://lists.debian.org/debian-lts-announce/2020/12/msg00032.html'
    label: report@snyk.io
  - url: 'https://snyk.io/vuln/SNYK-JS-INI-1048974'
    label: report@snyk.io
  - url: 'https://github.com/npm/ini/commit/56d2805e07ccd94e2ba0984ac9240ff02d44b6f1'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2020/12/msg00032.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://snyk.io/vuln/SNYK-JS-INI-1048974'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-7788.json
  - url: 'https://access.redhat.com/security/cve/CVE-2020-7788'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1907444'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2020-7788'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2020-7788'
  - url: 'https://access.redhat.com/errata/RHSA-2021:0521'
  - url: 'https://access.redhat.com/errata/RHSA-2021:0485'
  - url: 'https://access.redhat.com/errata/RHSA-2021:0421'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3281'
  - url: 'https://access.redhat.com/errata/RHSA-2021:3280'
  - url: 'https://access.redhat.com/errata/RHSA-2021:0548'
  - url: 'https://access.redhat.com/errata/RHSA-2021:0549'
  - url: 'https://access.redhat.com/errata/RHSA-2021:0551'
  - url: 'https://access.redhat.com/errata/RHSA-2022:0246'
  - url: 'https://access.redhat.com/errata/RHSA-2022:0350'
  - url: 'https://access.redhat.com/errata/RHSA-2021:5171'
  - url: 'https://access.redhat.com/errata/RHSA-2022:6595'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.03655
epssPercentile: 0.89314
ingestedAt: '2026-10-08T23:16:47.311Z'
---

## Overview

This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.

## Affected

- `ini < 1.3.6`
- `debian_linux = 9.0`

## Remediation

Upgrade past the affected range:

- `ini 1.3.6`

## Vendor advisories

- **RHSA-2021:0521** · Red Hat · fixed in: Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6), Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7), Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7), Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) · released 2021-02-15 · [advisory](https://access.redhat.com/errata/RHSA-2021:0521)
- **RHSA-2021:0485** · Red Hat · fixed in: Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6), Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7), Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7), Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) · released 2021-02-11 · [advisory](https://access.redhat.com/errata/RHSA-2021:0485)
- **RHSA-2021:0421** · Red Hat · fixed in: Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6), Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7), Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7), Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) · released 2021-02-04 · [advisory](https://access.redhat.com/errata/RHSA-2021:0421)
- **RHSA-2021:3281** · Red Hat · fixed in: Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7), Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7), Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) · released 2021-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2021:3281)
- **RHSA-2021:3280** · Red Hat · fixed in: Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.7), Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7), Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) · released 2021-08-26 · [advisory](https://access.redhat.com/errata/RHSA-2021:3280)
- **RHSA-2021:0548** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2021-02-16 · [advisory](https://access.redhat.com/errata/RHSA-2021:0548)
- **RHSA-2021:0549** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2021-02-16 · [advisory](https://access.redhat.com/errata/RHSA-2021:0549)
- **RHSA-2021:0551** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2021-02-16 · [advisory](https://access.redhat.com/errata/RHSA-2021:0551)
- **RHSA-2022:0246** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.8.4) · released 2022-01-25 · [advisory](https://access.redhat.com/errata/RHSA-2022:0246)
- **RHSA-2022:0350** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2022-02-01 · [advisory](https://access.redhat.com/errata/RHSA-2022:0350)
- **RHSA-2021:5171** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2021-12-16 · [advisory](https://access.redhat.com/errata/RHSA-2021:5171)
- **Red Hat VEX** · Moderate · affected: Red Hat Software Collections · no fix planned: Red Hat Software Collections · updated 2026-10-09 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2020/cve-2020-7788.json)
