CVE-2022-21122 Information
Jun 11, 2022
cve
Description
The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript’s Math class to the v8 context. As the Math class is exposed to user-land it can be used to get access to JavaScript’s Function constructor.
Reference
https://snyk.io/vuln/SNYK-JS-METACALC-2826197 https://github.com/metarhia/metacalc/commit/625c23d63eabfa16fc815f5832b147b08d2144bd https://github.com/metarhia/metacalc/pull/16
Share on: