CVE-2024-21537

HIGH

lilconfig 3.1.0 - Remote Code Execution via Insecure eval Usage in dynamicImport

Title source: llm
STIX 2.1

Description

Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious input through the defaultLoaders function.

Scores

CVSS v3 8.8
EPSS 0.0038
EPSS Percentile 59.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
n/a/lilconfig 3.1.0 - 3.1.1
npm/lilconfig 3.1.0 - 3.1.1npm
Published Oct 31, 2024
Tracked Since Feb 18, 2026