CVE-2020-7740
JavaScript vulnerability analysis and mitigation

Overview

CVE-2020-7740 affects all versions of the node-pdf-generator package. The vulnerability was discovered and assigned on January 21, 2020. The core issue stems from insufficient user input validation and sanitization of content provided to the node-pdf-generator package (NVD, CVE MITRE).

Technical details

The vulnerability exists due to a lack of proper input validation and sanitization mechanisms in the node-pdf-generator package. This security flaw specifically relates to how the package handles URLs that are passed to it for processing (NVD).

Impact

The vulnerability enables potential Server-Side Request Forgery (SSRF) attacks. An attacker can craft specific URLs that will be passed to an external server, potentially leading to unauthorized server requests (NVD).

Exploitability

The vulnerability can be exploited by crafting specific URLs that bypass the package's input validation. The attack vector requires the ability to pass content to the node-pdf-generator package (NVD).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-88062CRITICAL9.5
  • JavaScript logoJavaScript
  • omniroute
NoNoSep 10, 2026
CVE-2026-61534CRITICAL9.1
  • JavaScript logoJavaScript
  • yayson
NoYesSep 11, 2026
CVE-2026-59973HIGH8.5
  • JavaScript logoJavaScript
  • @frontmcp/adapters
NoYesSep 11, 2026
CVE-2026-59960HIGH7.5
  • JavaScript logoJavaScript
  • @argos-ci/core
NoYesSep 10, 2026
CVE-2026-59965HIGH7.1
  • JavaScript logoJavaScript
  • @jhb.software/payload-alt-text-plugin
NoNoSep 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management