Skip to main content
CRITICAL

CVE-2020-15123

CVSS v3

9.3

CRITICAL

EPSS Score

3.8 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. A similar CVE (CVE-2020-7597 for GHSA-5q88-cjfq-g2mh) was issued but the fix was incomplete. It only blocked &, and command injection is still possible using backticks instead to bypass the sanitizer. The attack surface is low in this case. Particularly in the standard use of codecov, where the module is used directly in a build pipeline, not built against as a library in another application that may supply malicious input and perform command injection.

Technical details

Published
2020-07-20

Frequently asked questions

What is CVE-2020-15123?

In codecov (npm package) before version 3.7.1 the upload method has a command injection vulnerability. Clients of the codecov-node library are unlikely to be aware of this, so they might unwittingly write code that contains a vulnerability. A similar CVE (CVE-2020-7597 for GHSA-5q88-cjfq-g2mh) was issued but the fix was incomplete. It only blocked &, and command injection is still possible using backticks instead to bypass the sanitizer. The attack surface is low in this case. Particularly in the standard use of codecov, where the module is used directly in a build pipeline, not built against as a library in another application that may supply malicious input and perform command injection.

Is CVE-2020-15123 actively exploited?

Active exploitation of CVE-2020-15123 has not been confirmed. Its EPSS score was 3.8% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-15123?

CVE-2020-15123 has a CVSS v3 base score of 9.3 (CRITICAL severity).

Is CVE-2020-15123 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key