{"id":"CVE-2024-40453","aliases":["GHSA-w5pw-gmcw-rfc8"],"url":"https://o3.security/vulnerability/CVE-2024-40453","summary":"squirrelly Code Injection vulnerability","details":"squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName.","published":"2024-08-21T00:00:00Z","modified":"2026-08-12T03:51:16.286544828Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"squirrelly","fixedVersion":"9.1.0"}],"fix":{"url":"https://github.com/squirrellyjs/squirrelly/pull/262","label":"squirrellyjs/squirrelly#262"},"references":[{"type":"WEB","url":"https://samuzora.com/posts/cve-2024-40453"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/40xxx/CVE-2024-40453.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-40453"},{"type":"FIX","url":"https://github.com/squirrellyjs/squirrelly/pull/262"},{"type":"PACKAGE","url":"https://github.com/squirrellyjs/squirrelly"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:16.286544828Z"}}