Vulnerability Details CVE-2022-21122
The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 80.7%
CVSS Severity
CVSS v3 Score 9.0
CVSS v2 Score 7.5
Products affected by CVE-2022-21122
-
cpe:2.3:a:metarhia:metacalc:-
-
cpe:2.3:a:metarhia:metacalc:0.0.1