Field Assessment
AI analysis pending.
Exhibit — Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Detected Signals
arbitrary code execution code execution
GitHub PoC Links
Note: these links are listed for security research and verification purposes only.
CVE
CVE-2017-1001002
Severity
CRITICAL
CVSS
9.8
EPSS
2.36%
Java
Original Filing — NVD Description
math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.