CVE-2020-7794

This affects all versions of package buns. The injection point is located in line 678 in index file lib/index.js in the exported function install(requestedModule).

Credits

JHU System Security Lab

References