CVE-2013-4660: Nodeca Js-Yaml
Medium severity, CVSS 6.8. EPSS: 17.3% chance of exploitation in the next 30 days.
The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that triggers an eval operation.
Affected products
- Nodeca Js-Yaml: up to and including 2.0.4; version 0.2.0 only; version 0.2.1 only; version 0.2.2 only; version 0.3.0 only; version 0.3.1 only; …
Published 2013-06-28. Last modified 2026-06-16.