Logo
vulnerabilityCVE-2023-39333
Name
CVE-2023-39333
Source
NVD ( link)Debian ( link)
Description
Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not have access to, similar to as if the WebAssembly module was a JavaScript module. This vulnerability affects users of any active release line of Node.js. The vulnerable feature is only available if Node.js is started with the `--experimental-wasm-modules` command line option.
Published Date
Updated Date
Workaround
-
Advisories

Analysis#


Affected Component
Analysis
nodejs
Patched

Vulnerability Ratings#


5.3
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
22.22.0
Not Affected
buildroot
master
22.22.0
Not Affected
openwrt
master
22.23.0-r1
Not Affected
openwrt
openwrt-25.12
22.23.0-r1
Not Affected
yocto
master
24.17.0
Not Affected
yocto
scarthgap
20.20.2
Not Affected

Resolved with patches#


nodejs (yocto:kirkstone)

#
Title
Author
Resolve
1
module: fix code injection through export names
Gyorgy Sarvari <skandigraun@gmail.com>
CVE-2023-39333