Vulnerabilities/

Arbitrary Code Execution in mathjs

Severity:
High

Description

math.js before 3.17.0 had an issue where private properties such as a constructor could be replaced by using unicode characters when creating an object.

Recommendation

Update the mathjs package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mathjs
Anything's wrong? Let us know Last updated on September 12, 2023

This issue is available in SmartScanner Professional

See Pricing