Espruino · Espruino · CVE-2020-19693
**Name of the Vulnerable Software and Affected Versions**
Espruino version 6ea4c0a
**Description**
An issue in Espruino allows an attacker to execute arbitrary code via the `oldFunc` parameter of the "jswrap object.c:jswrap function replacewith" endpoint.
**Recommendations**
For Espruino version 6ea4c0a, consider disabling the `jswrap function replacewith` function until a patch is available to prevent exploitation. Avoid using the `oldFunc` parameter in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.