CVE-2020-27637: R-Project Cran

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. Update to version 4.0.3

Affected products

  • R-Project Cran: before 4.0.3 (fixed in 4.0.3)

Published 2021-01-12. Last modified 2026-06-17.