{"id":"GHSA-w5pw-gmcw-rfc8","summary":"squirrelly Code Injection vulnerability","details":"squirrellyjs squirrelly v9.0.0 was discovered to contain a code injection vulnerability via the component `options.varName`. The issue was fixed in version 9.1.0.","aliases":["CVE-2024-40453"],"modified":"2024-08-21T20:27:34.934145Z","published":"2024-08-21T18:31:28Z","database_specific":{"cwe_ids":["CWE-94"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-08-21T20:09:15Z","nvd_published_at":"2024-08-21T17:15:08Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-40453"},{"type":"WEB","url":"https://github.com/squirrellyjs/squirrelly/pull/262"},{"type":"WEB","url":"https://github.com/squirrellyjs/squirrelly/commit/426f930e5ca1501404cd887071e734ec5feb0bcf"},{"type":"PACKAGE","url":"https://github.com/squirrellyjs/squirrelly"},{"type":"WEB","url":"https://samuzora.com/posts/cve-2024-40453"}],"affected":[{"package":{"name":"squirrelly","ecosystem":"npm","purl":"pkg:npm/squirrelly"},"ranges":[{"type":"SEMVER","events":[{"introduced":"9.0.0"},{"fixed":"9.1.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-w5pw-gmcw-rfc8/GHSA-w5pw-gmcw-rfc8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"}]}