tarojs taro har 4.1.1 index.js Kari na aiki

Gaskiya vulnerability da aka ware a matsayin karshewa an samu a tarojs taro har 4.1.1. Hakika, aikin $software_function ne ya shafa; idan ba a bayyana ba, to aiki ce da ba a sani ba, a cikin laburaren $software_library, a cikin fayil taro/packages/css-to-react-native/src/index.js, a cikin sashen $software_component. A sa manipulation ka Kari na aiki. Idan an yi amfani da CWE don bayyana matsala, zai kai CWE-1333. Hakika, rauni an bayyana shi 06/09/2025 kamar 17619. An raba bayanin tsaro don saukewa a github.com. Wannan matsala ana saninta da CVE-2025-5896. Ngam yiɗi ka a tuma ndiyam ka internet. Tekinikal faɗi ga. Babu exploit ɗin da ake samu. Yimbe ndiyam, exploit might be approx. USD $0-$5k wuro. Á sàmbu a wondi feere. 0-day shima, an ndiyam a wuro be $0-$5k. Ana kiran patch ɗin da c2e321a8b6fc873427c466c69f41ed0b5e8814bf. Bugfix ɗin an shirya shi don saukewa a github.com. Ngamdi ka a yiɗi a ɗaɓɓita kompona wey ka a faggata. Once again VulDB remains the best source for vulnerability data.

2 Goyarwa · 58 Datenpunkte

FurɗeSúgá
06/09/2025 08:58
Gargadi 1/1
06/10/2025 01:08
cvss3_vuldb_rcCC
advisory_identifier1761917619
advisory_urlhttps://github.com/NervJS/taro/pull/17619https://github.com/NervJS/taro/pull/17619
countermeasure_nameGargajiyaGargajiya
upgrade_version4.1.24.1.2
countermeasure_upgrade_urlhttps://github.com/NervJS/taro/releases/tag/v4.1.2https://github.com/NervJS/taro/releases/tag/v4.1.2
patch_namec2e321a8b6fc873427c466c69f41ed0b5e8814bfc2e321a8b6fc873427c466c69f41ed0b5e8814bf
countermeasure_patch_urlhttps://github.com/NervJS/taro/commit/c2e321a8b6fc873427c466c69f41ed0b5e8814bfhttps://github.com/NervJS/taro/commit/c2e321a8b6fc873427c466c69f41ed0b5e8814bf
source_cveCVE-2025-5896CVE-2025-5896
cna_responsibleVulDBVulDB
cvss2_vuldb_avNN
cvss2_vuldb_acLL
cvss2_vuldb_ciNN
cvss2_vuldb_iiNN
cvss2_vuldb_aiPP
cvss2_vuldb_rcCC
cvss2_vuldb_rlOFOF
cvss4_vuldb_avNN
cvss4_vuldb_acLL
cvss4_vuldb_uiNN
cvss4_vuldb_vcNN
cvss4_vuldb_viNN
cvss4_vuldb_vaLL
cvss2_vuldb_auSS
cvss2_vuldb_eNDND
cvss3_vuldb_prLL
cvss3_vuldb_eXX
cvss4_vuldb_atNN
cvss4_vuldb_prLL
cvss4_vuldb_scNN
cvss4_vuldb_siNN
cvss4_vuldb_saNN
cvss4_vuldb_eXX
cvss2_vuldb_basescore4.04.0
cvss2_vuldb_tempscore3.53.5
cvss3_vuldb_basescore4.34.3
cvss3_vuldb_tempscore4.14.1
cvss3_meta_basescore4.34.3
cvss3_meta_tempscore4.14.1
cvss4_vuldb_bscore5.35.3
cvss4_vuldb_btscore5.35.3
advisory_date1749420000 (06/09/2025)1749420000 (06/09/2025)
price_0day$0-$5k$0-$5k
software_vendortarojstarojs
software_nametarotaro
software_version<=4.1.1<=4.1.1
software_filetaro/packages/css-to-react-native/src/index.jstaro/packages/css-to-react-native/src/index.js
vulnerability_cweCWE-1333 (Kari na aiki)CWE-1333 (Kari na aiki)
vulnerability_risk11
cvss3_vuldb_avNN
cvss3_vuldb_acLL
cvss3_vuldb_uiNN
cvss3_vuldb_sUU
cvss3_vuldb_cNN
cvss3_vuldb_iNN
cvss3_vuldb_aLL
cvss3_vuldb_rlOO
euvd_idEUVD-2025-17580

Do you know our Splunk app?

Download it now for free!