Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2020-7774: y18n: Malicious data can be written to the global namespace

CVE-2020-7774 · published today
Summary

The y18n package, used for internationalization, allows an attacker to inject malicious code into the global scope, potentially leading to unexpected behavior or security issues. This affects developers who use y18n in their projects. To fix the issue, update y18n to version 3.2.2, 4.0.1, or 5.0.5 or later.

What to do
  • Update oss-bot y18n to version 3.2.2.
  • Update oss-bot y18n to version 4.0.1.
  • Update oss-bot y18n to version 5.0.5.
  • Update y18n to version 4.0.0-aikido.1.
  • Update rootio @rootio/y18n to version 4.0.0-root.io.1.
  • Update siemens sinec_infrastructure_network_services to version 1.0.1.1 or later.
Affected software
Ecosystem VendorProductAffected versions
npm oss-bot y18n < 3.2.2
4.0.0
>= 5.0.0, < 5.0.5
Fix: upgrade to 3.2.2
y18n_project y18n < 3.2.2
>= 5.0.0, < 5.0.5
4.0.0
cpe:2.3:a:y18n_project:y18n:*:*:*:*:*:node.js:*:*
oracle graalvm 19.3.5
20.3.1.2
21.0.0.2
cpe:2.3:a:oracle:graalvm:19.3.5:*:*:*:enterprise:*:*:*
siemens sinec_infrastructure_network_services < 1.0.1.1
cpe:2.3:a:siemens:sinec_infrastructure_network_services:*:*:*:*:*:*:*:*
Root:npm y18n < 4.0.0-aikido.1
Fix: upgrade to 4.0.0-aikido.1
Root:npm rootio @rootio/y18n < 4.0.0-root.io.1
Fix: upgrade to 4.0.0-root.io.1
Original advisory text
CVE-2020-7774 in y18n - Patched by Root
Root has patched CVE-2020-7774 in the y18n package for Root:npm. Multiple fixed versions available.
Severity
9.8 Critical
CVSS 3.1: 7.3 (GHSA)
Exploitation
EPSS 69%
Type
CWE-20Improper Input Validation
CWE-915Improperly Controlled Modification of Dynamically-Determined Object Attributes
CWE-1321Prototype Pollution
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen6 Mar 2026
Monitor software like this
Free during beta