GHSA-f5x2-xv93-4p23 · Severity: critical · Ecosystem: npm — Access of Resource Using Incompatible Type in Facebook Hermes
A type confusion vulnerability when resolving properties of JavaScript objects with specially-crafted prototype chains in Facebook Hermes prior to commit fe52854cdf6725c2eaa9e125995da76e6ceb27da allows attackers to potentially execute arbitrary code via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
Conclusion & alert: CVE-2020-1911 is rated High Risk (67.5/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 2.00%). Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 1.02% | 2.00% | +0.99% |
| 2 | 2025-03-30 | 2.81% | 1.02% | -1.80% |
| 3 | 2025-03-29 | — | 2.81% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 6.8 | 2.0 | MEDIUM |
|
8.6 | 6.4 | [email protected] |
GHSA-f5x2-xv93-4p23 · Severity: critical · Ecosystem: npm — Access of Resource Using Incompatible Type in Facebook Hermes
| URL | Tags |
|---|---|
| https://github.com/facebook/hermes/commit/fe52854cdf6725c2eaa9e125995da76e6ceb27da | Patch Third Party Advisory |
| https://www.facebook.com/security/advisories/cve-2020-1911 | Third Party Advisory |