StackRadar

CVE-2020-7608

Medium

Advisory

Published 4 Sept 2020In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.005
42nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
109
of 17,781 indexed, latest versions
Container images
108
deployed by those charts
Fix available
1 of 1
affected package

yargs-parser Vulnerable to Prototype Pollution

Carried by container images the latest versions of 109 of 17,781 indexed charts deploy, on 108 images.

Affected packageAffected versionsFixed inImages
yargs-parsernpm2.4.1, 3.2.0, 4.2.1, 5.0.0+6 more5.0.1, 13.1.2108
OSV records
GHSA-p9pc-299p-vxgp
Also known as
SNYK-JS-YARGSPARSER-560381

Charts affected

109 by stars
ChartLatestAffected imagesRadar Score
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2020-7608.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
yargs-parser@9.0.2
13.1.2

Open the chart page →

29,220
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2020-7608.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
yargs-parser@9.0.2
13.1.2

Open the chart page →

29,220
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2020-7608.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
yargs-parser@9.0.2
13.1.2

Open the chart page →

3,881
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2020-7608.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
yargs-parser@9.0.2
13.1.2

Open the chart page →

4,967
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2020-7608.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
yargs-parser@9.0.2
13.1.2

Open the chart page →

3,827
joplintobiassackmann0.1.71 of 2See more

joplin tobiassackmann 0.1.7

1 of the 2 container images this version deploys carry CVE-2020-7608.

Container imageDigestPackageFixed in
joplin/server:latest3f7b852959aa
yargs-parser@7.0.0
13.1.2

Open the chart page →

5,535
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2020-7608.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
yargs-parser@7.0.0
13.1.2

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2020-7608.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
yargs-parser@7.0.0
13.1.2

Open the chart page →

22,665
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7608.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
yargs-parser@9.0.2
13.1.2

Open the chart page →

1,309

Container images carrying it

108 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
yargs-parser@13.0.0
13.1.2
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
yargs-parser@13.0.0
13.1.2
1
ghcr.io/leoquote/mergeable:latest451706815103
yargs-parser@9.0.2
13.1.2
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
yargs-parser@9.0.2
13.1.2
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
yargs-parser@11.1.1
13.1.2
1
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
yargs-parser@9.0.2
13.1.2
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
yargs-parser@9.0.2
13.1.2
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
yargs-parser@9.0.2
13.1.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.