2017-11-27 14:00:00
joshbressers
PUBLISHED
math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.