VDB
Sign up
CRITICAL9.0

GHSA-5gc4-cx9x-9c43

Code Injection in metacalc

Quick fix

GHSA-5gc4-cx9x-9c43 — metacalc: upgrade to the fixed version with the command below.

npm install metacalc@0.0.2

Details

The package metacalc before 0.0.2 is vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/metacalc
Introduced in: 0Fixed in: 0.0.2
Fixnpm install metacalc@0.0.2

References