← Back to browse · API

CVE-2021-23389

Severity
CRITICAL
CVSS
9.8
EPSS
0.03603
Risk score
40.46
CISA KEV
No
PoC
No
Published
2021-07-12
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-2469, GHSA-7FM6-GXQG-2PWR
Products
n/a:total.js unspecified <3.4.9
Sources
euvd EUVD-2021-2469

Description

The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

References