Impact
A crafted payload sent to the UniscriptExecutionService.execute() function in Univer enables attackers to run arbitrary code on the host. The weakness lies in insufficient validation or sanitization, allowing code generation and execution, which qualifies as Command Injection or Improper Control of Code Execution.
Affected Systems
The affected product is Univer version 1.0.0-alpha.2. No vendor name is specified in the available data.
Risk and Exploitability
The vulnerability carries a high risk of exploitation because it permits remote code execution. No EPSS score is published, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers would need to deliver a crafted request to the vulnerable service endpoint, likely over the network, since the service is exposed via the /services/script-execution.service.ts path. Given the nature of the flaw, exploitation could compromise confidentiality, integrity, and availability of the affected system.
OpenCVE Enrichment