CVE-2020-24025: Sass-Lang Node-Sass
Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.
Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.
Affected products
- Sass-Lang Node-Sass: from 2.0.0, up to and including 4.14.1
Published 2021-01-11. Last modified 2026-06-17.