← Vulnerability feed

Vulnerability record · CVE-2020-7774 · published 17 November 2020

CVE-2020-7774: y18n prototype pollution via crafted input

YY18n Project · Y18n

The y18n package before 3.2.2, 4.0.1 and 5.0.5 is vulnerable to prototype pollution. Because y18n is a widely used dependency for CLI localization, the flaw can be pulled into many applications and build pipelines, making it a broad supply-chain concern.

9.8 CVSS 3.1 Critical EPSS 69% · top 0.7% CWE-1321 · Prototype pollution
9.8CVSS 3.1 base score, v2 7.5
69%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
12References, 6 tagged exploit
17 Jun 2026Last modified by NVD

Description

The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCritical CVSS 9.8 and very high EPSS with public exploit references, though not in KEV and requiring a reachable vulnerable code path.

What it is

The y18n package before 3.2.2, 4.0.1 and 5.0.5 is vulnerable to prototype pollution. Because y18n is a widely used dependency for CLI localization, the flaw can be pulled into many applications and build pipelines, making it a broad supply-chain concern.

Impact

An attacker can pollute Object.prototype, which may lead to denial of service, logic bypass, or in some contexts remote code execution depending on how the polluted properties are consumed.

Attack surface

The vulnerability is network-reachable with no privileges or user interaction required per the CVSS vector, meaning it can be triggered by supplying crafted input to code paths that use y18n.

Exploitation

CVE-2020-7774 is not listed in CISA KEV, but EPSS is very high at 0.694 (99.3rd percentile) and multiple references are tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade y18n to 3.2.2, 4.0.1, 5.0.5 or later, and update dependent packages that bundle it.
  • Apply vendor patches for Oracle and Siemens products that embed the affected library.
  • Run dependency scanning to find transitive copies of y18n in your build and runtime trees.
  • Block or sanitize untrusted input that reaches object merge or configuration parsing paths.
  • Freeze Object.prototype in sensitive processes where feasible to limit pollution impact.

Detection

  • Search dependency manifests and lockfiles for y18n versions below the fixed releases.
  • Monitor for unexpected properties added to Object.prototype in runtime instrumentation.
  • Alert on anomalous process behavior or crashes in Node.js services that use y18n.
  • Review CI/CD logs for dependency resolution pulling vulnerable y18n versions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-7774 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-41993Apple WebKit improper check allows arbitrary code executionCVE-2023-41993 is a WebKit flaw where processing web content can lead to arbitrary code execution, addressed with improved checks. Apple states it is…KEVEPSS 24%analysed9.8CVE-2020-27304Civetweb project civetweb relative path traversal vulnerabilityThe CivetWeb web library does not validate uploaded filepaths when running on an OS other than Windows, when using the built-in HTTP form-based file …EPSS 3.2%9.8CVE-2021-22930Nodejs node.js use after free vulnerabilityNode.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to a use after free attack where an attacker might be able to exploit the memory corruption…EPSS 36%9.8CVE-2021-22931Nodejs node.js improper input validation vulnerabilityNode.js before 16.6.0, 14.17.4, and 12.22.4 is vulnerable to Remote Code Execution, XSS, Application crashes due to missing input validation of host …EPSS 22%9.8CVE-2021-29921Python vulnerabilityIn Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) all…EPSS 6.9%9.8CVE-2021-25216BIND GSS-TSIG SPNEGO Memory Corruption Enables Crash and Possible RCEBIND servers configured with GSS-TSIG (via tkey-gssapi-keytab or tkey-gssapi-credential) use an ISC SPNEGO implementation that mishandles input, caus…EPSS 82%analysed9.8CVE-2020-11656Sqlite use after free vulnerabilityIn SQLite through 3.31.1, the ALTER TABLE implementation has a use-after-free, as demonstrated by an ORDER BY clause that belongs to a compound SELEC…EPSS 7.6%9.8CVE-2019-15605Node.js HTTP request smuggling via malformed Transfer-EncodingNode.js versions 10, 12 and 13 mishandle malformed Transfer-Encoding headers, allowing HTTP request smuggling. This lets an attacker desynchronize fr…EPSS 57%analysed

Source: NIST National Vulnerability Database (record CVE-2020-7774), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.