CVE-2020-24025: Sass-Lang Node-Sass

Medium severity, CVSS 5.3. EPSS: 0.8% chance of exploitation in the next 30 days.

Certificate validation in node-sass 2.0.0 to 4.14.1 is disabled when requesting binaries even if the user is not specifying an alternative download path.

Affected products

  • Sass-Lang Node-Sass: from 2.0.0, up to and including 4.14.1

Published 2021-01-11. Last modified 2026-06-17.