{"id":"GHSA-vwhc-pww7-72x6","summary":"Code Injection in total.js","details":"Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. In total.js framework before version 3.4.9, calling the utils.set function with user-controlled values leads to code-injection. This can cause a variety of impacts that include arbitrary code execution. This is fixed in version 3.4.9.","aliases":["CVE-2021-32831"],"modified":"2023-11-08T04:06:01.802752Z","published":"2021-09-01T18:24:05Z","database_specific":{"nvd_published_at":"2021-08-30T21:15:00Z","cwe_ids":["CWE-94"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-08-31T20:25:52Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32831"},{"type":"WEB","url":"https://github.com/totaljs/framework/commit/887b0fa9e162ef7a2dd9cec20a5ca122726373b3"},{"type":"PACKAGE","url":"https://github.com/totaljs"},{"type":"WEB","url":"https://github.com/totaljs/framework/blob/e644167d5378afdc45cb0156190349b2c07ef235/changes.txt#L11"},{"type":"ADVISORY","url":"https://securitylab.github.com/advisories/GHSL-2021-066-totaljs-totaljs"},{"type":"WEB","url":"https://www.npmjs.com/package/total.js"}],"affected":[{"package":{"name":"total.js","ecosystem":"npm","purl":"pkg:npm/total.js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.4.9"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/09/GHSA-vwhc-pww7-72x6/GHSA-vwhc-pww7-72x6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H"}]}