CVE-2024-23347

Publication date

2024-01-16 17:57:20

Family

facebook

State

PUBLISHED

Description

Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.