{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-01T18:34:16.154","vulnerabilities":[{"cve":{"id":"CVE-2020-7749","sourceIdentifier":"report@snyk.io","published":"2020-10-20T11:15:12.660","lastModified":"2026-06-17T03:25:22.653","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"This affects all versions of package osm-static-maps. User input given to the package is passed directly to a template without escaping ({{{ ... }}}). As such, it is possible for an attacker to inject arbitrary HTML/JS code and depending on the context. It will be outputted as an HTML on the page which gives opportunity for XSS or rendered on the server (puppeteer) which also gives opportunity for SSRF and Local File Read."},{"lang":"es","value":"Esto afecta a todas las versiones del paquete osm-static-maps.&#xa0;Una entrada de usuario dada al paquete es pasada directamente a una plantilla sin escapar ({{{...}}}).&#xa0;Como tal, es posible que un atacante inyecte código HTML/JS arbitrario y dependiendo del contexto.&#xa0;Se generará como un HTML en la página que otorga la oportunidad de un XSS o se renderizaba en el servidor (puppeteer) que también otorga la oportunidad de un SSRF y una lectura de archivos locales"}],"affected":[{"source":"report@snyk.io","affectedData":[{"vendor":"n/a","product":"osm-static-maps","versions":[{"version":"0","lessThan":"unspecified","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"report@snyk.io","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L","baseScore":7.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"LOW","availabilityImpact":"LOW"},"exploitabilityScore":2.8,"impactScore":4.7}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-74"},{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:osm-static-maps_project:osm-static-maps:*:*:*:*:*:node.js:*:*","matchCriteriaId":"02D6B0BB-1A95-4C5B-861B-598C32A63812"}]}]}],"references":[{"url":"https://github.com/jperelli/osm-static-maps/blob/master/src/template.html%23L142","source":"report@snyk.io","tags":["Broken Link"]},{"url":"https://github.com/jperelli/osm-static-maps/pull/24","source":"report@snyk.io","tags":["Patch","Third Party Advisory"]},{"url":"https://snyk.io/vuln/SNYK-JS-OSMSTATICMAPS-609637","source":"report@snyk.io","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/jperelli/osm-static-maps/blob/master/src/template.html%23L142","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"]},{"url":"https://github.com/jperelli/osm-static-maps/pull/24","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://snyk.io/vuln/SNYK-JS-OSMSTATICMAPS-609637","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]}]}}]}