CVE-2024-39173: 253153 Calculator-Boilerplate
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
calculator-boilerplate v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the eval function at /routes/calculator.js. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the input field.
Affected products
- 253153 Calculator-Boilerplate: version 1.0 only
Published 2024-07-18. Last modified 2026-06-17.