Vulnerability record · CVE-2020-7774 · published 17 November 2020
CVE-2020-7774: y18n prototype pollution via crafted input
YY18n Project · Y18n
The y18n package before 3.2.2, 4.0.1 and 5.0.5 is vulnerable to prototype pollution. Because y18n is a widely used dependency for CLI localization, the flaw can be pulled into many applications and build pipelines, making it a broad supply-chain concern.
Description
The package y18n before 3.2.2, 4.0.1 and 5.0.5, is vulnerable to Prototype Pollution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS 9.8 and very high EPSS with public exploit references, though not in KEV and requiring a reachable vulnerable code path.
What it is
The y18n package before 3.2.2, 4.0.1 and 5.0.5 is vulnerable to prototype pollution. Because y18n is a widely used dependency for CLI localization, the flaw can be pulled into many applications and build pipelines, making it a broad supply-chain concern.
Impact
An attacker can pollute Object.prototype, which may lead to denial of service, logic bypass, or in some contexts remote code execution depending on how the polluted properties are consumed.
Attack surface
The vulnerability is network-reachable with no privileges or user interaction required per the CVSS vector, meaning it can be triggered by supplying crafted input to code paths that use y18n.
Exploitation
CVE-2020-7774 is not listed in CISA KEV, but EPSS is very high at 0.694 (99.3rd percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade y18n to 3.2.2, 4.0.1, 5.0.5 or later, and update dependent packages that bundle it.
- Apply vendor patches for Oracle and Siemens products that embed the affected library.
- Run dependency scanning to find transitive copies of y18n in your build and runtime trees.
- Block or sanitize untrusted input that reaches object merge or configuration parsing paths.
- Freeze Object.prototype in sensitive processes where feasible to limit pollution impact.
Detection
- Search dependency manifests and lockfiles for y18n versions below the fixed releases.
- Monitor for unexpected properties added to Object.prototype in runtime instrumentation.
- Alert on anomalous process behavior or crashes in Node.js services that use y18n.
- Review CI/CD logs for dependency resolution pulling vulnerable y18n versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | PatchThird Party Advisory |
| https://github.com/yargs/y18n/issues/96 | ExploitThird Party Advisory |
| https://github.com/yargs/y18n/pull/108 | PatchThird Party Advisory |
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1038306 | ExploitThird Party Advisory |
| https://snyk.io/vuln/SNYK-JS-Y18N-1021887 | ExploitThird Party Advisory |
| https://www.oracle.com/security-alerts/cpuApr2021.html | PatchThird Party Advisory |
| https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdf | PatchThird Party Advisory |
| https://github.com/yargs/y18n/issues/96 | ExploitThird Party Advisory |
| https://github.com/yargs/y18n/pull/108 | PatchThird Party Advisory |
| https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1038306 | ExploitThird Party Advisory |
| https://snyk.io/vuln/SNYK-JS-Y18N-1021887 | ExploitThird Party Advisory |
| https://www.oracle.com/security-alerts/cpuApr2021.html | PatchThird Party Advisory |
Track CVE-2020-7774 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-7774), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.