Remote Code Execution (RCE)
Discription

js2py is vulnerable to Remote Code Execution (RCE). The vulnerability is due to the js2py.disable_pyimport() function failing to prevent JS sandbox escape, which allows an attacker to send crafted API calls which results in arbitrary code…Read More

Back to Main

Subscribe for the latest news: