# sonatype-2020-0781

## lodashs, loadyml, loadyaml - Malicious Packages

**Published:** Aug 27, 2020

**CVSS Score:** Critical 9.1

## Security Details

### Components Impacted

### Sonatype Research

#### sonatype-2020-0781 Security Details

**CVE ID:** sonatype-2020-0781  
**CVE Description:** lodashs, loadyml, loadyaml - Malicious Packages  
**Published:** Aug 27, 2020  
**CVSS Score & Severity:** 9.1 Critical  
**CVSS Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N  
**EPSS Score:** 0%

### Malware
malware

### KEV Status
Not in KEV Catalog: No known exploits

### Affected Ecosystems
affected

### Source
Sonatype

### References
- [Sonatype Blog](https://blog.sonatype.com/sonatype-spots-malicious-npm-packages)  
- [Sonatype Help](https://help.sonatype.com/en/sonatype-malware-data.html)  
- [OSV](https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-25475.json)
