Impact
A flaw in the Syncfusion ej2-javascript-ui-controls package allows a local attacker to use the child_process.exec function in the package.json file to inject arbitrary operating system commands. The weakness is an OS command injection, which can lead to execution of unintended commands on the host system, potentially compromising data, modifying or deleting files, or escalating privileges if the process runs with elevated rights.
Affected Systems
The vendor Syncfusion offers the ej2-javascript-ui-controls library, which is impacted in all releases up to version 33.2.3. Any installation of the library within that version range is potentially exploitable until an updated release is applied.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity. Exploitation is limited to situations where an attacker has local access to the environment in which the vulnerable library is running. The EPSS score is < 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a very low overall likelihood of real‑world exploitation. However, because the flaw requires local execution, the risk is significant in contexts where local users or compromised users can run the library, allowing the injection of arbitrary OS commands.
OpenCVE Enrichment