CVE-2014-7205: Bassmaster Project Bassmaster

High severity, CVSS 10.0. EPSS: 78.6% chance of exploitation in the next 30 days.

Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors.

Affected products

Published 2014-10-08. Last modified 2026-06-17.