CVE detail
CVE-2020-26226 — CVE-2020-26226
Published 2020-11-18 · Modified 2026-06-17 · Vendor semantic-release_project · Product semantic-release · Source nvd
HIGH
severity
CVSS-derived band
0.0138
EPSS probability
exploitation probability, 30d
70.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
In the npm package semantic-release before version 17.2.3, secrets that would normally be masked by `semantic-release` can be accidentally disclosed if they contain characters that become encoded when included in a URL. Secrets that do not contain characters that become encoded when included in a URL are already masked properly. The issue is fixed in version 17.2.3.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References