Loading HuntDB...

GHSA-ch4x-f5c4-36gv

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

A security flaw in Node.js allows a bypass of network import restrictions.
By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security.
Verified on various platforms, the vulnerability is mitigated by forbidding data URLs in network imports.
Exploiting this flaw can violate network import security, posing a risk to developers and servers.

Related CVEs

Key Information

GHSA ID
GHSA-ch4x-f5c4-36gv
Published
July 9, 2024 3:31 AM
Last Modified
November 22, 2024 12:39 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.