Description
Valine v1.4.18 was discovered to contain a remote code execution (RCE) vulnerability which allows attackers to execute arbitrary code via a crafted POST request.
Remediation
References
https://github.com/xCss/Valine/issues/400
Related Vulnerabilities
CVE-2023-25576 Vulnerability in npm package @fastify/multipart
CVE-2021-23497 Vulnerability in npm package @strikeentco/set
CVE-2016-10735 Vulnerability in npm package bootstrap
CVE-2022-36083 Vulnerability in npm package jose
CVE-2020-5497 Vulnerability in maven package org.mitre:openid-connect-common