TopVuln

High-risk vulnerability digests

CVE-2024-21541

  • MEDIUM

report@snyk.io

Details

CVSS v3
7.3
CVSS v4
5.5
NVD published
2024-11-13 05:15:14
Affected versions
cpe:2.3:a:matthewmueller:dom-iterator:*:*:*:*:*:node.js:*:*
Summary
Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body and thus care must be given to ensure that the inputs to Function are not attacker-controlled. The risks involved are similar to that of allowing attacker-controlled input to reach eval.
Remediation
Not available in our cache.
Exploit info
https://security.snyk.io/vuln/SNYK-JS-DOMITERATOR-6157199

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.