An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.
{
"nvd_published_at": "2024-06-20T17:15:50Z",
"cwe_ids": [
"CWE-94"
],
"severity": "HIGH",
"github_reviewed_at": "2024-06-20T19:19:56Z",
"github_reviewed": true
}