{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-04T04:13:48.955","vulnerabilities":[{"cve":{"id":"CVE-2020-7748","sourceIdentifier":"report@snyk.io","published":"2020-10-20T11:15:12.583","lastModified":"2026-06-17T03:25:22.540","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"This affects the package @tsed/core before 5.65.7. This vulnerability relates to the deepExtend function which is used as part of the utils directory. Depending on if user input is provided, an attacker can overwrite and pollute the object prototype of a program."},{"lang":"es","value":"Esto afecta al paquete @tsed/core versiones anteriores a 5.65.7.&#xa0;Esta vulnerabilidad se relaciona con la función deepExtend que es usada como parte del directorio utils.&#xa0;Dependiendo de si se proporciona la entrada de usuario, un atacante puede sobrescribir y contaminar el prototipo de objeto de un programa"}],"affected":[{"source":"report@snyk.io","affectedData":[{"vendor":"n/a","product":"@tsed/core","versions":[{"version":"unspecified","lessThan":"5.65.7","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"report@snyk.io","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L","baseScore":5.6,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.2,"impactScore":3.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":8.1,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.2,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-1321"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ts.ed_project:ts.ed:*:*:*:*:*:node.js:*:*","versionEndExcluding":"5.65.7","matchCriteriaId":"A1F64D2D-8888-42D4-96A9-02C14AEAEE65"}]}]}],"references":[{"url":"https://github.com/TypedProject/tsed/blob/production/packages/core/src/utils/deepExtends.ts%23L36","source":"report@snyk.io","tags":["Broken Link","Patch","Third Party Advisory"]},{"url":"https://github.com/TypedProject/tsed/commit/1395773ddac35926cf058fc6da9fb8e82266761b","source":"report@snyk.io","tags":["Patch","Third Party Advisory"]},{"url":"https://snyk.io/vuln/SNYK-JS-TSEDCORE-1019382","source":"report@snyk.io","tags":["Exploit","Patch","Third Party Advisory"]},{"url":"https://github.com/TypedProject/tsed/blob/production/packages/core/src/utils/deepExtends.ts%23L36","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link","Patch","Third Party Advisory"]},{"url":"https://github.com/TypedProject/tsed/commit/1395773ddac35926cf058fc6da9fb8e82266761b","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://snyk.io/vuln/SNYK-JS-TSEDCORE-1019382","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Third Party Advisory"]}]}}]}