CVE-2020-28438: Deferred-Exec Project Deferred-Exec

Critical severity, CVSS 9.8. EPSS: 1.3% chance of exploitation in the next 30 days.

This affects all versions of package deferred-exec. The injection point is located in line 42 in lib/deferred-exec.js

Affected products

Published 2022-07-25. Last modified 2026-06-17.