Description
Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-20852 | Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application. |
References
| Link | Providers |
|---|---|
| https://www.facebook.com/security/advisories/cve-2024-23347 |
|
History
Fri, 20 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2025-06-20T17:54:46.578Z
Reserved: 2024-01-15T19:19:44.939Z
Link: CVE-2024-23347
Updated: 2024-08-01T22:59:32.227Z
Status : Modified
Published: 2024-01-16T18:15:11.267
Modified: 2025-06-20T18:15:28.087
Link: CVE-2024-23347
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD