VYPR
Critical severity9.8NVD Advisory· Published Jul 12, 2021· Updated Jun 17, 2026

CVE-2021-23390

CVE-2021-23390

Description

The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
total4npm
< 0.0.430.0.43

Affected products

3
  • total4/total4description
  • cpe:2.3:a:totaljs:total4:*:*:*:*:*:node.js:*:*
    Range: <0.0.43
  • ghsa-coords
    Range: < 0.0.43

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.