CVE detail
CVE-2020-7616 — CVE-2020-7616
Published 2020-04-07 · Modified 2026-06-17 · Vendor express-mock-middleware_project · Product express-mock-middleware · Source nvd
MEDIUM
severity
CVSS-derived band
0.0124
EPSS probability
exploitation probability, 30d
66.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack code can be placed which will then be exported by `express-mock-middleware`. As such, this is considered to be a low risk.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References