Loading HuntDB...

GHSA-jrvm-mcxc-mf6m

GitHub Security Advisory

dom-iterator code execution vulnerability

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body and thus care must be given to ensure that the inputs to Function are not attacker-controlled. The risks involved are similar to that of allowing attacker-controlled input to reach eval.

Affected Packages

npm dom-iterator
Affected versions: 0 (fixed in 1.0.1)

Related CVEs

Key Information

GHSA ID
GHSA-jrvm-mcxc-mf6m
Published
November 13, 2024 6:30 AM
Last Modified
January 14, 2025 9:18 PM
CVSS Score
5.0 /10
Primary Ecosystem
npm
Primary Package
dom-iterator
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.