Lucene search

K
cvelistMitreCVELIST:CVE-2013-4660
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2013-4660

2022-10-0316:14:58
mitre
www.cve.org
cve-2013-4660
remote code execution
node.js

7.5 High

AI Score

Confidence

Low

0.936 High

EPSS

Percentile

99.1%

The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that triggers an eval operation.

7.5 High

AI Score

Confidence

Low

0.936 High

EPSS

Percentile

99.1%