CVE Published: 16/01/2024 |
CVE Updated: 01/08/2024 |
CVE Year: 2024 Source: facebook |
Vendor: Meta Platforms, Inc |
Product: Meta Spark Studio Status : PUBLISHED
CVE-2024-23347 Description
Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.