CVE-2024-23347: Facebook Meta Spark Studio
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.
Affected products
- Facebook Meta Spark Studio: before 176 (fixed in 176)
Published 2024-01-16. Last modified 2026-06-17.