CVE-2020-28437: Heroku-Env Project Heroku-Env

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

This affects all versions of package heroku-env. The injection point is located in lib/get.js which is required by index.js.

Affected products

Published 2022-08-02. Last modified 2026-06-17.