Vulnerability DatabaseGHSA-p32g-242c-76h3

GHSA-p32g-242c-76h3
JavaScript vulnerability analysis and mitigation

Overview

A critical security vulnerability was identified in the npm package 'geoheat' version 1.3.2, discovered and disclosed on August 31, 2020. The vulnerability was published to the GitHub Advisory Database on September 11, 2020, and was last updated on July 27, 2023. This security issue affects specifically version 1.3.2 of the geoheat package (GitHub Advisory).

Technical details

The vulnerability involves malicious code embedded in version 1.3.2 of the geoheat package. When executed in a browser environment, the malicious code specifically targets form fields containing sensitive information, including passwords, CVC numbers, and credit card numbers. The compromised data is then exfiltrated to an external endpoint at js-metrics.com/minjs.php?pl= (GitHub Advisory).

Impact

The vulnerability poses a severe risk to user privacy and financial security as it specifically targets sensitive payment information including credit card numbers, CVC codes, and passwords from web forms. Any application incorporating the compromised version of the package could potentially expose users' financial data to unauthorized collection (GitHub Advisory).

Exploitability

The malicious code is automatically executed when the compromised package version is implemented in a browser environment, making it highly exploitable with no additional user interaction required. The code actively harvests sensitive data from form fields and transmits it to an external server (GitHub Advisory).

Mitigation and workarounds

Users are strongly advised to remove version 1.3.2 of the geoheat package from their environment immediately. It is recommended to conduct a thorough evaluation of applications to determine if any user data has been compromised. As a temporary solution, users can downgrade to version 1.3.1 of the package. No patches are available as this is a malicious package rather than a vulnerability that can be fixed (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55157HIGH8.4
  • JavaScript logoJavaScript
  • @ooples/token-optimizer-mcp
NoYesAug 14, 2026
CVE-2026-35219HIGH7.1
  • JavaScript logoJavaScript
  • @budibase/server
NoYesAug 14, 2026
CVE-2026-55156MEDIUM5.3
  • JavaScript logoJavaScript
  • @ooples/token-optimizer-mcp
NoYesAug 14, 2026
CVE-2026-50029MEDIUM5.3
  • JavaScript logoJavaScript
  • js-toml
NoYesAug 14, 2026
CVE-2026-73428MEDIUM4.6
  • JavaScript logoJavaScript
  • trix
NoYesAug 13, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management