CVE-2022-21122

Published
View on NVD ↗
CVSS v3
9
CRITICAL
CVSS v2
7.5
HIGH
Affected
1
PROJECT

Description

The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor.

Spreadsheet calculations for Metarhia 🧮
GitHubGitHub
11