Headline
GHSA-g7rj-q722-245g: jsreport vulnerable to code injection
jsreport prior to 3.11.3 had a version of vm2 vulnerable to CVE-2023-29017 hard coded in the package.json of the jsreport-core component. An attacker can use this vulnerability to obtain the authority of the jsreport playground server, or construct a malicious webpage/html file and send it to the user to attack the installed jsreport client.
jsreport vulnerable to code injection
Critical severity GitHub Reviewed Published May 8, 2023 to the GitHub Advisory Database • Updated May 9, 2023