{"id":"CVE-2017-1001004","aliases":["GHSA-3qh4-r86r-grvm"],"url":"https://o3.security/vulnerability/CVE-2017-1001004","summary":"Arbitrary JavaScript Execution in typed-function","details":"typed-function before 0.10.6 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.","published":"2017-11-27T14:29:00.333Z","modified":"2026-07-08T12:05:22.671451Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"typed-function","fixedVersion":"0.10.6"}],"fix":{"url":"https://github.com/josdejong/typed-function/commit/6478ef4f2c3f3c2d9f2c820e2db4b4ba3425e6fe","label":"josdejong/typed-function@6478ef4"},"references":[{"type":"WEB","url":"https://github.com/josdejong/typed-function/blob/master/HISTORY.md#2017-11-18-version-0106"},{"type":"FIX","url":"https://github.com/josdejong/typed-function/commit/6478ef4f2c3f3c2d9f2c820e2db4b4ba3425e6fe"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T12:05:22.671451Z"}}