Arbitrary Code Execution in mathjs
Critical severity
GitHub Reviewed
Published
Dec 18, 2017
to the GitHub Advisory Database
•
Updated Sep 12, 2023
Description
Published to the GitHub Advisory Database
Dec 18, 2017
Reviewed
Jun 16, 2020
Last updated
Sep 12, 2023
math.js before 3.17.0 had an issue where private properties such as a constructor could be replaced by using unicode characters when creating an object.
Recommendation
Upgrade to version 3.17.0 or later.
References