HIGH8.1
GHSA-9p6p-8v9r-8c9m
javascript-deobfuscator crafted payload can lead to code execution
Quick fix
GHSA-9p6p-8v9r-8c9m — js-deobfuscator: upgrade to the fixed version with the command below.
npm install js-deobfuscator@1.1.0Details
javascript-deobfuscator removes common JavaScript obfuscation techniques. Crafted payloads targeting expression simplification can lead to code execution. This issue has been patched in version 1.1.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/ben-sb/javascript-deobfuscator/security/advisories/GHSA-9p6p-8v9r-8c9m[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-36120[ADVISORY]
- https://github.com/ben-sb/javascript-deobfuscator/commit/630d3caec83d5f31c5f7a07e6fadf613d06699d6[WEB]
- https://github.com/ben-sb/javascript-deobfuscator[PACKAGE]