VYPR

Jsen

by Jsen Project

CVEs (1)

  • CVE-2020-7777HigNov 23, 2020
    risk 0.47cvss 7.2epss 0.02

    This affects all versions of package jsen. If an attacker can control the schema file, it could run arbitrary JavaScript code on the victim machine. In the module description and README file there is no mention about the risks of untrusted schema files, so I assume that this is…