CVE-2024-36120

HIGH

javascript-deobfuscator <1.1.0 - RCE

Title source: llm
STIX 2.1

Description

javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targeting expression simplification can lead to code execution. This issue has been patched in version 1.1.0. Users are advised to update. Users unable to upgrade should disable the expression simplification feature.

Scores

CVSS v3 8.1
EPSS 0.0029
EPSS Percentile 52.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (2)
deobfuscate/javascript_deobfuscator < 1.1.0
npm/js-deobfuscator 0 - 1.1.0npm
Published May 31, 2024
Tracked Since Feb 18, 2026