CVE-2017-16020: Summit Project Summit
Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.
Affected products
- Summit Project Summit: from 0.1.0, up to and including 0.1.21
Published 2018-06-04. Last modified 2026-06-17.