Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2020-7788: INI Package Parses Malicious Files, Exposes Application to Further Attacks

CVE-2020-7788 · published today
Summary

The ini package before version 1.3.6 can be exploited by an attacker submitting a malicious INI file, potentially allowing them to compromise the application's security. This can lead to further vulnerabilities depending on the application's context. You should update the ini package to version 1.3.6 or later to prevent this issue.

What to do
  • Update GitHub Actions ini to version 1.3.6.
  • Update ini to version 1.3.5-aikido.1.
  • Update rootio @rootio/ini to version 1.3.5-root.io.1.
  • Update ini_project ini to version 1.3.6 or later.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions ini < 1.3.6
Fix: upgrade to 1.3.6
ini_project ini < 1.3.6
cpe:2.3:a:ini_project:ini:*:*:*:*:*:node.js:*:*
debian debian_linux 9.0
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
Root:npm ini < 1.3.5-aikido.1
Fix: upgrade to 1.3.5-aikido.1
Root:npm rootio @rootio/ini < 1.3.5-root.io.1
Fix: upgrade to 1.3.5-root.io.1
Original advisory text
CVE-2020-7788 in ini - Patched by Root
Root has patched CVE-2020-7788 in the ini package for Root:npm. Multiple fixed versions available.
Severity
9.8 Critical
CVSS 3.1: 7.3 (GHSA)
Exploitation
EPSS 4%
Type
CWE-1321Prototype Pollution
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen6 Mar 2026
Monitor software like this
Free during beta