PT-2023-7025 · Node.Js+6 · Node.Js+6

Dittyroma

·

Published

2023-07-28

·

Updated

2026-05-18

·

CVE-2023-39333

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Node.js versions prior to the fixed version
Description Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not have access to, similar to as if the WebAssembly module was a JavaScript module. This issue affects users of any active release line of Node.js, but the vulnerable feature is only available if Node.js is started with the --experimental-wasm-modules command line option.
Recommendations As a temporary workaround, consider disabling the --experimental-wasm-modules command line option until a patch is available. Restrict access to the WebAssembly module to minimize the risk of exploitation. Avoid using the vulnerable feature until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Improper Neutralization

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2023:5849
ALSA-2023:5869
ALSA-2023:7205
BDU:2023-08046
BIT-NODE-2023-39333
BIT-NODE-MIN-2023-39333
CESA-2023_5869
CESA-2023_7205
CLEANSTART-2026-BD71263
CLEANSTART-2026-IS74202
CLEANSTART-2026-JR35772
CLEANSTART-2026-JY06700
CLEANSTART-2026-KN34553
CLEANSTART-2026-KZ45320
CLEANSTART-2026-LJ44720
CLEANSTART-2026-LN12820
CLEANSTART-2026-TX00223
CLEANSTART-2026-WI75198
CVE-2023-39333
DSA-5589-1
MGASA-2023-0299
OPENSUSE-SU-2023_4207-1
OPENSUSE-SU-2024:13337-1
OPENSUSE-SU-2024:13340-1
RHSA-2023:5849
RHSA-2023:5869
RHSA-2023:7205
RHSA-2023_5849
RHSA-2023_5869
RHSA-2023_7205
RLSA-2023:7205
SUSE-SU-2023:4132-1
SUSE-SU-2023:4133-1
SUSE-SU-2023:4150-1
SUSE-SU-2023:4155-1
SUSE-SU-2023:4207-1

Affected Products

Almalinux
Centos
Node.Js
Red Hat
Red Os
Rocky Linux
Suse