Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2020-7788: INI Package Parses Malicious Files, Exposes Application to Further Attacks
CVE-2020-7788 · published today
Summary
The ini package before version 1.3.6 can be exploited by an attacker submitting a malicious INI file, potentially allowing them to compromise the application's security. This can lead to further vulnerabilities depending on the application's context. You should update the ini package to version 1.3.6 or later to prevent this issue.
What to do
- Update GitHub Actions ini to version 1.3.6.
- Update ini to version 1.3.5-aikido.1.
- Update rootio @rootio/ini to version 1.3.5-root.io.1.
- Update ini_project ini to version 1.3.6 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| npm | GitHub Actions | ini |
< 1.3.6 Fix: upgrade to 1.3.6
|
| – | ini_project | ini |
< 1.3.6 cpe:2.3:a:ini_project:ini:*:*:*:*:*:node.js:*:* |
| – | debian | debian_linux |
9.0 cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| Root:npm | – | ini |
< 1.3.5-aikido.1 Fix: upgrade to 1.3.5-aikido.1
|
| Root:npm | rootio | @rootio/ini |
< 1.3.5-root.io.1 Fix: upgrade to 1.3.5-root.io.1
|
Original advisory text
CVE-2020-7788 in ini - Patched by Root
Root has patched CVE-2020-7788 in the ini package for Root:npm. Multiple fixed versions available.
References
- https://github.com/npm/ini/commit/56d2805e07ccd94e2ba0984ac9240ff02d44b6f1
- https://www.npmjs.com/advisories/1589
- https://snyk.io/vuln/SNYK-JS-INI-1048974
- https://nvd.nist.gov/vuln/detail/CVE-2020-7788
- https://lists.debian.org/debian-lts-announce/2020/12/msg00032.html
- https://github.com/advisories/GHSA-qqgx-2p2h-9c37
Severity
9.8
Critical
CVSS 3.1: 7.3 (GHSA)
Exploitation
EPSS 4%
Type
CWE-1321Prototype Pollution
Timeline
Published3 Sep 2026
Updated3 Sep 2026
First seen6 Mar 2026
Monitor software like this
Free during beta