Arbitrary Code Execution in mathjs
Critical severity
GitHub Reviewed
Published
Dec 18, 2017
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Published to the GitHub Advisory Database
Dec 18, 2017
Reviewed
Jun 16, 2020
Last updated
Jan 9, 2023
math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.
Recommendation
Update to version 3.17.0 or later.
References