PT-2024-4746 · Pypi+1 · Js2Py+1

Marven11

·

Published

2024-02-28

·

Updated

2026-02-03

·

CVE-2024-28397

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions js2py versions prior to 0.74 python-Js2Py versions prior to 0.74-3.1 (openSUSE Tumbleweed) pyload-ng versions less than or equal to 0.5.0b3.dev85 (when used with Python 3.11 or below)
Description A sandbox escape issue exists in the js2py.disable pyimport() component of js2py, allowing attackers to execute arbitrary code via a crafted API call. This vulnerability, identified as CVE-2024-28397, can be exploited by sending a malicious JavaScript payload to the application. The vulnerability allows bypassing sandbox restrictions and executing commands on the system. The pyload-ng application, when using js2py with Python 3.11 or below, is vulnerable through its /flash/addcrypted2 API endpoint. An attacker can bypass localhost restrictions using HTTP headers to access this endpoint and achieve Remote Code Execution (RCE). Millions of Python users are potentially affected, as js2py is a widely used library with over 1 million monthly downloads.
Recommendations js2py versions prior to 0.74: Upgrade to a newer version that addresses this vulnerability. python-Js2Py versions prior to 0.74-3.1 (openSUSE Tumbleweed): Upgrade to version 0.74-3.1 or later. pyload-ng versions less than or equal to 0.5.0b3.dev85 (when used with Python 3.11 or below): Upgrade to a newer version of pyload-ng that addresses this vulnerability or use Python 3.12 or above.

Exploit

Fix

RCE

LPE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2024-05266
CVE-2024-28397
ECHO-AF95-1DA0-5A17
GHSA-H95X-26F3-88HR
GHSA-R9PP-R4XF-597R
MGASA-2024-0256
OPENSUSE-SU-2024:14086-1
OPENSUSE-SU-2024_2272-1
SUSE-SU-2024:2272-1

Affected Products

Suse
Js2Py