LiveActive security incident?Get immediate response
CVE Record

CVE-2020-7718: Prototype Pollution

All versions of package gammautils are vulnerable to Prototype Pollution via the deepSet and deepMerge functions.

CriticalCVSS 9.8Not KEV-listedUpdated
Glexia's TakeAutomated analysiscritical

Security readout for executives and security teams

Plain-English summary

CVE-2020-7718 affects the npm package gammautils. Its deepSet and deepMerge functions can allow prototype pollution, where attacker-controlled object properties may affect broader application behavior. The CVSS score is critical, but business urgency depends on whether gammautils is present and reachable with untrusted input.

Executive priority

Prioritize inventory and remediation for internet-facing or API-heavy JavaScript services. Treat confirmed reachable use as urgent because the published severity is critical and no fixed version is identified in the supplied sources.

Technical view

The source bundle describes prototype pollution in all versions of gammautils through deepSet and deepMerge. CVSS 3.1 is 9.8 with network attack vector, low complexity, no privileges, and no user interaction. The sources provided do not identify a fixed version or concrete vendor mitigation.

Likely exposure

Exposure is most likely in JavaScript or Node.js applications that include gammautils directly or transitively and use deepSet or deepMerge on attacker-influenced objects, JSON, request bodies, or configuration data.

Exploitation context

The bundle does not show CISA KEV listing or cited evidence of active exploitation. CVSS indicates remote, unauthenticated exploitability in principle, but real-world exploitability depends on application data flow and use of the affected functions.

Researcher notes

Evidence is limited to the CVE record, CVE List data, and Snyk reference. Do not assume exploit activity, affected applications, or a patch beyond those sources. Focus analysis on dependency presence and whether attacker-controlled keys reach deepSet or deepMerge.

Mitigation direction

  • Check vendor and Snyk guidance for current remediation or replacement advice.
  • Remove gammautils if unused or replace it with a maintained safer alternative.
  • Avoid passing untrusted input into deepSet or deepMerge.
  • Add validation that blocks dangerous object property names before deep merge operations.
  • Update lockfiles after remediation and redeploy affected applications.

Validation and detection

  • Search package manifests and lockfiles for gammautils direct or transitive usage.
  • Generate or review SBOMs for gammautils in deployed services.
  • Review code paths using deepSet or deepMerge with external input.
  • Run dependency scanning that detects CVE-2020-7718 or SNYK-JS-GAMMAUTILS-598670.
  • Confirm production artifacts no longer include vulnerable gammautils versions.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-7718 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Critical
CVSS
9.8 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
9.8CVSS 3.1CriticalCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C3.95.9Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

9.8Critical
CVSS 3.1 vector shape for CVE-2020-7718Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
n/agammautils0Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.