CVE-2020-7760
JavaScript vulnerability analysis and mitigation

Overview

CVE-2020-7760 affects the CodeMirror package before version 5.58.2, including org.apache.marmotta.webjars:codemirror. The vulnerability was discovered in October 2020 and impacts the JavaScript mode component of the CodeMirror text editor (Debian Advisory, Oracle Advisory).

Technical details

The vulnerability is related to a potentially exponential regular expression in the JavaScript mode component of CodeMirror. The issue was fixed by modifying the regular expression pattern that handles async keyword matching (GitHub Commit). The vulnerability has a CVSS 3.1 Base Score of 4.3 (Availability impacts), with attack vector being Network, low attack complexity, requiring low privileges, and no user interaction (Oracle Advisory).

Impact

Successful exploitation of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of systems using the affected CodeMirror component (Oracle Advisory).

Exploitability

The vulnerability is easily exploitable by low privileged attackers with network access via HTTP. It does not require user interaction to exploit (Oracle Advisory).

Mitigation and workarounds

The vulnerability has been fixed in CodeMirror version 5.58.2. Users should upgrade to this version or later to mitigate the issue. Debian has released security update DSA-4789-1 for the codemirror-js package to address this vulnerability (Debian Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-77415CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-77414CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-77413CRITICAL9.3
  • JavaScript logoJavaScript
  • jsonata
NoYesAug 21, 2026
CVE-2026-63421HIGH7.5
  • JavaScript logoJavaScript
  • @keystone-6/core
NoYesAug 21, 2026
CVE-2026-53509MEDIUM5.7
  • JavaScript logoJavaScript
  • @aborruso/ckan-mcp-server
NoYesAug 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management