CVE-2020-7720: Digitalbazaar Forge

High severity, CVSS 7.3. EPSS: 3.2% chance of exploitation in the next 30 days.

The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.

Affected products

Published 2020-09-01. Last modified 2026-06-17.