Vulnerabilities/

Command Injection in hot-formula-parser

Severity:
High

Description

Versions of hot-formula-parser prior to 3.0.1 are vulnerable to Command Injection. The package fails to sanitize values passed to the parse function and concatenates it in an eval call. If a value of the formula is supplied by user-controlled input it may allow attackers to run arbitrary commands in the server.

Recommendation

Update the hot-formula-parser package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
hot-formula-parser
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing