Unknown · Squirrelly · CVE-2024-40453
**Name of the Vulnerable Software and Affected Versions**
squirrellyjs squirrelly version 9.0.0
**Description**
The issue is a code injection vulnerability via the component `options.varName`. This vulnerability was discovered in squirrellyjs squirrelly and was fixed in version 9.0.1, however, another source indicates it was fixed in version 9.1.0.
**Recommendations**
For version 9.0.0, update to version 9.0.1 or 9.1.0 to resolve the issue.
As a temporary workaround, consider restricting the use of the `options.varName` component until a patch is applied.