StackRadar

CVE-2020-7660

High

Advisory

Published 11 Aug 2020In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.1
base score, highest
EPSS
0.026
84th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
16
of 17,781 indexed, latest versions
Container images
16
deployed by those charts
Fix available
1 of 1
affected package

Insecure serialization leading to RCE in serialize-javascript

Carried by container images the latest versions of 16 of 17,781 indexed charts deploy, on 16 images.

Affected packageAffected versionsFixed inImages
serialize-javascriptnpm1.6.1, 1.7.0, 1.9.1, 2.1.23.1.016
OSV records
GHSA-hxcc-f52p-wc94

Charts affected

16 by stars
ChartLatestAffected imagesRadar Score
flagsmithone-acre-fundVerified publisher0.1.51 of 6See more

flagsmith one-acre-fund 0.1.5

1 of the 6 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
serialize-javascript@1.7.0
3.1.0

Open the chart page →

6,868
mastodondefault-ghVerified publisher0.3.11 of 3See more

mastodon default-gh 0.3.1

1 of the 3 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
serialize-javascript@2.1.2
3.1.0

Open the chart page →

5,056
testhubteshubVerified publisher0.1.41 of 3See more

testhub teshub 0.1.4

1 of the 3 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
testhubio/testhub-frontend:on-preme86c2db53be8
serialize-javascript@2.1.2
3.1.0

Open the chart page →

7,517
angular-chartangular-application0.1.01 of 1See more

angular-chart angular-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
ibarreche/cloud-front-ci:latestc8970ac1c8dc
serialize-javascript@1.9.1
3.1.0

Open the chart page →

3,237
daskcloudnativeapp2.2.11 of 2See more

dask cloudnativeapp 2.2.1

1 of the 2 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
daskdev/dask-notebook:1.1.0052630f5ca04
serialize-javascript@1.6.1
3.1.0

Open the chart page →

29,901
developer-dashboardcloud-native-toolkit1.4.11 of 1See more

developer-dashboard cloud-native-toolkit 1.4.1

1 of the 1 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
serialize-javascript@2.1.2
3.1.0

Open the chart page →

25,456
conduction-uiconduction-ui0.1.01 of 6See more

conduction-ui conduction-ui 0.1.0

1 of the 6 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
conduction/conduction-ui-app:devd591f5e6f2a9
serialize-javascript@1.9.1
3.1.0

Open the chart page →

12,907
amundsenduyet1.1.01 of 7See more

amundsen duyet 1.1.0

1 of the 7 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
amundsendev/amundsen-frontend:2.1.169e7915e61c1
serialize-javascript@2.1.2
3.1.0

Open the chart page →

11,174
ibm-app-navigatoribm-charts1.0.11 of 5See more

ibm-app-navigator ibm-charts 1.0.1

1 of the 5 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
ibmcom/app-nav-ui:1.0.1e2a86997b36b
serialize-javascript@1.7.0
3.1.0

Open the chart page →

32,915
yapijoelee2012Verified publisher0.2.01 of 1See more

yapi joelee2012 0.2.0

1 of the 1 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
jayfong/yapi:1.10.2163e5d621910
serialize-javascript@1.9.1
3.1.0

Open the chart page →

6,454
opendistro-eslsst-sqre1.4.11 of 3See more

opendistro-es lsst-sqre 1.4.1

1 of the 3 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
serialize-javascript@1.7.0
3.1.0

Open the chart page →

7,929
frontendluiscajl0.1.71 of 1See more

frontend luiscajl 0.1.7

1 of the 1 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
lavandadelpatio/frontend:latest501c3f31e0bc
serialize-javascript@2.1.2
3.1.0

Open the chart page →

3,651
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
serialize-javascript@1.9.1
3.1.0

Open the chart page →

6,524
mastodonrivals-spaceVerified publisher3.1.21 of 3See more

mastodon rivals-space 3.1.2

1 of the 3 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
serialize-javascript@2.1.2
3.1.0

Open the chart page →

6,026
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
serialize-javascript@2.1.2
3.1.0

Open the chart page →

3,696
fdi-dotstatsuite-dlmstatcan0.3.11 of 1See more

fdi-dotstatsuite-dlm statcan 0.3.1

1 of the 1 container images this version deploys carry CVE-2020-7660.

Container imageDigestPackageFixed in
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
serialize-javascript@1.9.1
3.1.0

Open the chart page →

3,881

Container images carrying it

16 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
amazon/opendistro-for-elasticsearch-kibana:1.4.05126e2e79a1f
serialize-javascript@1.7.0
3.1.0
1
amundsendev/amundsen-frontend:2.1.169e7915e61c1
serialize-javascript@2.1.2
3.1.0
1
conduction/conduction-ui-app:devd591f5e6f2a9
serialize-javascript@1.9.1
3.1.0
1
daskdev/dask-notebook:1.1.0052630f5ca04
serialize-javascript@1.6.1
3.1.0
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
serialize-javascript@1.7.0
3.1.0
1
ibarreche/cloud-front-ci:latestc8970ac1c8dc
serialize-javascript@1.9.1
3.1.0
1
ibmcom/app-nav-ui:1.0.1e2a86997b36b
serialize-javascript@1.7.0
3.1.0
1
jayfong/yapi:1.10.2163e5d621910
serialize-javascript@1.9.1
3.1.0
1
lavandadelpatio/frontend:latest501c3f31e0bc
serialize-javascript@2.1.2
3.1.0
1
ondrejsika/parking:latestb1fd497416c8
serialize-javascript@2.1.2
3.1.0
1
phntom/codimd:2.4.31b9aafbb62e6
serialize-javascript@1.9.1
3.1.0
1
siscc/dotstatsuite-data-lifecycle-manager:v14.0.0b6f9a7c888fc
serialize-javascript@1.9.1
3.1.0
1
testhubio/testhub-frontend:on-preme86c2db53be8
serialize-javascript@2.1.2
3.1.0
1
ghcr.io/mastodon/mastodon:v4.1.26b18e6d0eda4
serialize-javascript@2.1.2
3.1.0
1
ghcr.io/rivals-space/rivals-mastodon:1.6.143b23d55e4be
serialize-javascript@2.1.2
3.1.0
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
serialize-javascript@2.1.2
3.1.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.