Vulnerabilities/

React Editable Json Tree vulnerable to arbitrary code execution via function parsing

Severity:
High

Description

Our library allows strings to be parsed as functions and stored as a specialized component, JsonFunctionValue. To do this, Javascript’s eval function was used to execute strings that begin with “function” as Javascript.

Recommendation

Update the react-editable-json-tree package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
react-editable-json-tree
Anything's wrong? Let us know Last updated on January 30, 2023

This issue is available in SmartScanner Professional

See Pricing