View at Official debian advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2020-8141 not yet assigned priority: Debian including 1 source packages (node-dot), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5.
The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype.