CVE-2024-23347: Facebook Meta Spark Studio

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Prior to v176, when opening a new project Meta Spark Studio would execute scripts defined inside of a package.json file included as part of that project. Those scripts would have the ability to execute arbitrary code on the system as the application.

Affected products

  • Facebook Meta Spark Studio: before 176 (fixed in 176)

Published 2024-01-16. Last modified 2026-06-17.