VDB
Sign up
CRITICAL9.8

GHSA-p6x5-p4xf-cc4r

Remote Code Execution (RCE) via String Literal Injection into math-codegen

Quick fix

GHSA-p6x5-p4xf-cc4r — math-codegen: upgrade to the fixed version with the command below.

npm install math-codegen@0.4.3

Details

### Impact

String literal content passed to `cg.parse()` is injected verbatim into a `new Function()` body without sanitization. This allows an attacker to execute arbitrary system commands when user-controlled input reaches the parser. Any application exposing a math evaluation endpoint where user input flows into `cg.parse()` is vulnerable to full RCE. ### Patches

The vulnerability is addressed by using `JSON.stringify()` on string literal values in `lib/node/ConstantNode.js` to ensure they are treated as data rather than code. Users should upgrade to version 0.4.3 or later. ### Workarounds

Avoid passing un-sanitized user input to the parser or manually escape string literals in the input.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/math-codegen
Introduced in: 0Fixed in: 0.4.3
Fixnpm install math-codegen@0.4.3

References