{"schema_version":"1.9.0","id":"GHSA-p9pc-299p-vxgp","published":"2020-09-04T18:00:54Z","modified":"2026-07-08T06:49:37.726276553Z","aliases":["CVE-2020-7608","SNYK-JS-YARGSPARSER-560381"],"summary":"yargs-parser Vulnerable to Prototype Pollution","details":"Affected versions of `yargs-parser` are vulnerable to prototype pollution. Arguments are not properly sanitized, allowing an attacker to modify the prototype of `Object`, causing the addition or modification of an existing property that will exist on all objects.  \nParsing the argument `--foo.__proto__.bar baz'` adds a `bar` property with value `baz` to all objects. This is only exploitable if attackers have control over the arguments being passed to `yargs-parser`.\n\n\n\n## Recommendation\n\nUpgrade to versions 13.1.2, 15.0.1, 18.1.1 or later.","affected":[{"package":{"name":"yargs-parser","ecosystem":"npm","purl":"pkg:npm/yargs-parser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"6.0.0"},{"fixed":"13.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-p9pc-299p-vxgp/GHSA-p9pc-299p-vxgp.json"}},{"package":{"name":"yargs-parser","ecosystem":"npm","purl":"pkg:npm/yargs-parser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"14.0.0"},{"fixed":"15.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-p9pc-299p-vxgp/GHSA-p9pc-299p-vxgp.json"}},{"package":{"name":"yargs-parser","ecosystem":"npm","purl":"pkg:npm/yargs-parser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"16.0.0"},{"fixed":"18.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-p9pc-299p-vxgp/GHSA-p9pc-299p-vxgp.json"}},{"package":{"name":"yargs-parser","ecosystem":"npm","purl":"pkg:npm/yargs-parser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.0.1"}]}],"database_specific":{"last_known_affected_version_range":"<= 5.0.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-p9pc-299p-vxgp/GHSA-p9pc-299p-vxgp.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7608"},{"type":"WEB","url":"https://github.com/yargs/yargs-parser/commit/1c417bd0b42b09c475ee881e36d292af4fa2cc36"},{"type":"WEB","url":"https://github.com/yargs/yargs-parser/commit/63810ca1ae1a24b08293a4d971e70e058c7a41e2"},{"type":"PACKAGE","url":"https://github.com/yargs/yargs-parser"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1500"}],"database_specific":{"cwe_ids":["CWE-1321","CWE-915"],"github_reviewed":true,"github_reviewed_at":"2020-08-31T19:01:32Z","nvd_published_at":"2020-03-16T20:15:00Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}]}