CVE-2014-7205: Bassmaster Project Bassmaster
High severity, CVSS 10.0. EPSS: 78.6% chance of exploitation in the next 30 days.
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors.
Affected products
- Bassmaster Project Bassmaster: before 1.5.2 (fixed in 1.5.2)
Published 2014-10-08. Last modified 2026-06-17.