CVE-2017-16020: Summit Project Summit

Critical severity, CVSS 9.8. EPSS: 2.5% chance of exploitation in the next 30 days.

Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.

Affected products

Published 2018-06-04. Last modified 2026-06-17.