CVE-2020-28494
JavaScript vulnerability analysis and mitigation

Overview

The vulnerability CVE-2020-28494 affects the total.js package versions before 3.4.7. The issue was discovered in the image.pipe and image.stream functions, where the type parameter is used to build commands that are executed using child_process.spawn. The vulnerability was disclosed on January 29, 2021 (Snyk Report).

Technical details

The vulnerability occurs because child_process.spawn is called with the option shell set to true and the type parameter is not properly sanitized. This implementation flaw allows for potential command injection attacks. The vulnerability has been assigned a CVSS v3.1 score of 8.6 (HIGH) by Snyk, indicating significant severity (Snyk Report).

Impact

A successful exploitation of this vulnerability could result in command injection, potentially leading to arbitrary code execution on the affected system. The attack could result in total loss of confidentiality with high impact, while having lower impact on system integrity and availability (Snyk Report).

Exploitability

The vulnerability is remotely exploitable and requires no special privileges or user interaction. Snyk has confirmed the existence of a proof-of-concept exploit, indicating that the vulnerability is practically exploitable (Snyk Report).

Mitigation and workarounds

The vulnerability has been fixed in total.js version 3.4.7. Users are recommended to upgrade to this version or higher to mitigate the risk. The fix includes proper validation of supported image types through a whitelist implementation (Github Commit).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-63376HIGH8.2
  • JavaScript logoJavaScript
  • cockpit-image-builder.src
NoYesSep 03, 2026
GHSA-7q9c-hpx7-9cwmHIGH7.5
  • JavaScript logoJavaScript
  • @typespec/spector
NoYesSep 04, 2026
CVE-2026-77465HIGH7.5
  • JavaScript logoJavaScript
  • toml
NoYesSep 03, 2026
CVE-2026-71429MEDIUM6.2
  • JavaScript logoJavaScript
  • stream-json
NoYesSep 03, 2026
GHSA-6hxq-p678-4hr2LOW2
  • JavaScript logoJavaScript
  • @simplewebauthn/server
NoYesSep 04, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management