Description
This is critical vulnerability, as it allows to run arbitrary code on any server using superjson input, including a Blitz.js server, without prior authentication or knowledge. Attackers gain full control over the server so they could steal and manipulate data or attack further systems.
Recommendation
Update the superjson package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.8.1
- Patched version(s): 1.8.1
References
- GHSA-5888-ffcr-r425
- www.sonarsource.com
- CVE-2022-23631
- CWE-1321
- CWE-94
- CAPEC-310
- OWASP 2021-A3
- OWASP 2021-A6
Related Issues
- Joplin Remote Code Execution - CVE-2022-40277
- @saltcorn/server Remote Code Execution (RCE) / SQL injection via prototype pollution by manipulating `lang` and `defst - Vulnerability
- angular-base64-upload vulnerable to unauthenticated remote code execution - CVE-2024-42640
- Angular Expressions - Remote Code Execution - CVE-2021-21277
You might also like:
- Tags:
- npm
- superjson
Anything's wrong? Let us know Last updated on November 01, 2023


