CVE-2020-27637: R-Project Cran
Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.
The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD install cli command or the install.packages() function from the interpreter. Update to version 4.0.3
Affected products
- R-Project Cran: before 4.0.3 (fixed in 4.0.3)
Published 2021-01-12. Last modified 2026-06-17.