CVE-2020-7651: Synk Broker

Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.

All versions of snyk-broker before 4.79.0 are vulnerable to Arbitrary File Read. It allows partial file reads for users who have access to Snyk's internal network via patch history from GitHub Commits API.

Affected products

  • Synk Broker: before 4.79.0 (fixed in 4.79.0)

Published 2020-05-29. Last modified 2026-06-17.