Aller au contenu

Fiche vulnérabilité

CVE-2022-21122 : faille critique metarhia metacalc (CVSS 9.8)

Description

The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
8 juin 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • metarhia metacalc

Références

Rechercher une autre vulnérabilité dans la base CVE