Open Source Software
CVE-2020-1340 — NuGetGallery Spoofing Vulnerability
Executive Summary
A spoofing vulnerability exists when the NuGetGallery does not properly sanitize input on package metadata values. An attacker who successfully exploited the vulnerability could perform cross-site scripting attacks and run scripts in the security context of the user viewing the malicious content. To exploit this vulnerability, an attacker with permissions to upload packages could publish specially crafted content on a gallery page. The security update addresses the vulnerability by correcting how NuGetGallery sanitizes input.
Overview
5.4
CVSS MEDIUM
Important
MS Severity
Not Exploited
MS Exploit Status
Less Likely
MS Exploit Likelihood
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
ATTACK VECTOR
Network
ATTACK COMPLEXITY
Low
PRIVILEGES REQUIRED
Low
USER INTERACTION
Required
SCOPE
Changed
EPSS Score
0.01578
probability of exploitation in the next 30 days
0.72287 percentile - updated 2026-06-21
View on FIRST.org
Affected Products
1 affected product
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| NuGetGallery | Github Repo (Security Update) |
Important | Spoofing | Maybe |
Patches
1 patch
| Article | Type | Restart |
|---|---|---|
Github Repo |
Security Update | Maybe |
Known Exploits
No known exploits have been linked for this CVE yet. When available, exploit references will be sourced from public repositories and may be unverified, incomplete, or non-functional. Always review code carefully before use in any environment.
Acknowledgments
Gabriel Thau
References
On This Page