In the Node.js version 18.x and 20.x a high severity vulnerability CVE-2023-39333 was detected. This vulnerability allows attackers to inject JavaScript code into a WebAssembly module via maliciously crafted export names, potentially gaining access to data and functions that should be restricted. To fix this problem, users should upgrade Node.js to version 20.8.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2023-39333.
Node.js: Upgrade Required to Fix JavaScript Injection Flaw”
by the Hossted team
11.09.2024