Vulnerability in the Python package Js2Py, downloaded over a million times a month
A vulnerability (CVE-2024-28397) has been discovered in the Python package Js2Py, which was downloaded 1.2 million times last month, allowing bypassing of sandbox isolation and execution of code in the system when processing specially crafted JavaScript data. The vulnerability can be exploited to attack programs that use Js2Py to execute JavaScript code. A fix is currently available only as a patch. A prototype for testing the attack potential has been prepared […]
