← Back to browse · API

CVE-2025-55346

Severity
CRITICAL
CVSS
9.8
EPSS
0.18448
Risk score
45.66
CISA KEV
No
PoC
No
Published
2025-08-14
Modified
2025-08-14
First seen
2026-08-07
Aliases
EUVD-2025-24803, GHSA-HMGH-466J-FX4C, GHSA-Q4XX-MC3Q-23X8
Products
-
Sources
euvd EUVD-2025-24803

Description

User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS code in the context of the host, by sending a simple POST request.

References