Critical severity9.8NVD Advisory· Published Dec 31, 2018· Updated Jun 17, 2026
CVE-2018-6333
CVE-2018-6333
Description
The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content inside of the editor's context, which could potentially be chained to lead to code execution. This issue affected Nuclide prior to v0.290.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nuclidenpm | < 0.290.0 | 0.290.0 |
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/facebook/nuclide/commit/65f6bbd683404be1bb569b8d1be84b5d4c74a324nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-r83x-wj75-v89rghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-6333ghsaADVISORY
News mentions
0No linked articles in our index yet.