CVE-2023-45311

CRITICAL EXPLOITED

fsevents < 1.2.11 - Remote Code Execution via Untrusted Binary Download URL

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2023-45311 has been observed exploited in the wild (reported by VulnCheck KEV).

Description

fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was controlled by an adversary. NOTE: some sources feel that this means that no version is affected any longer, because the URL is not controlled by an adversary.

Scores

CVSS v3 9.8
EPSS 0.0088
EPSS Percentile 75.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2025-11-26
CWE
CWE-94
Status published
Products (2)
fsevents_project/fsevents < 1.2.11
npm/fsevents 0 - 1.2.11npm
Published Oct 06, 2023
Tracked Since Feb 18, 2026