Back
CVE-2020-8137
CRITICAL
Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker.
Published: Mar 20, 2020
Modified: Jun 17, 2026
CWE-94
CWE-94
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (1)
| Vendor | Product | Version |
|---|---|---|
| blamer_project | blamer | * < 1.0.1 |
GitHub Security Advisory GHSA-7vm7-j8p7-h346
Code injection in blamer
npm
blamer
<= 1.0.0
Fixed: 1.0.1
References (2)
- https://hackerone.com/reports/772448 Exploit, Patch, Third Party Advisory
- https://hackerone.com/reports/772448 Exploit, Patch, Third Party Advisory
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
4.27%
Top 10% most likely to be exploited
Threat Score
40.5 / 100
Data Sources
NVD
EPSS
GitHub