CVE-2020-28445: Npm-Help Project Npm-Help

Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.

This affects all versions of package npm-help. The injection point is located in line 13 in index.js file in export.latestVersion() function.

Affected products

Published 2022-07-25. Last modified 2026-06-17.