CVE-2024-21541
Severity CVSS v4.0:
MEDIUM
Type:
CWE-94
Code Injection
Publication date:
13/11/2024
Last modified:
14/01/2025
Description
Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body and thus care must be given to ensure that the inputs to Function are not attacker-controlled. The risks involved are similar to that of allowing attacker-controlled input to reach eval.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM
Base Score 3.x
7.30
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:matthewmueller:dom-iterator:*:*:*:*:*:node.js:*:* | 1.0.0 (including) |
To consult the complete list of CPE names with products and versions, see this page



