The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-5939 The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor.
Github GHSA Github GHSA GHSA-5gc4-cx9x-9c43 Code Injection in metacalc
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published:

Updated: 2024-09-16T19:56:29.255Z

Reserved: 2022-02-24T00:00:00

Link: CVE-2022-21122

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-06-08T09:15:08.470

Modified: 2024-11-21T06:43:56.573

Link: CVE-2022-21122

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses