CVE-2022-21122
Estado: ModificadaCrítica (9.8)—
The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 9.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 2.51%
- Percentil entre todas las CVEs puntuadas: 84
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-94
Referencias
- https://github.com/metarhia/metacalc/commit/625c23d63eabfa16fc815f5832b147b08d2144bd
- https://github.com/metarhia/metacalc/pull/16
- https://snyk.io/vuln/SNYK-JS-METACALC-2826197
- https://github.com/metarhia/metacalc/commit/625c23d63eabfa16fc815f5832b147b08d2144bd
- https://github.com/metarhia/metacalc/pull/16
- https://snyk.io/vuln/SNYK-JS-METACALC-2826197
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-21122",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "report@snyk.io",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 9,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 6,
"exploitabilityScore": 2.2
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 9.8,
"attackVector": "NETWORK",
"baseSeverity": "CRITICAL",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "report@snyk.io",
"affectedData": [
{
"vendor": "n/a",
"product": "metacalc",
"versions": [
{
"status": "affected",
"version": "unspecified",
"lessThan": "0.0.2",
"versionType": "custom"
}
]
}
]
}
],
"published": "2022-06-08T09:15:08.470",
"references": [
{
"url": "https://github.com/metarhia/metacalc/commit/625c23d63eabfa16fc815f5832b147b08d2144bd",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/metarhia/metacalc/pull/16",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://snyk.io/vuln/SNYK-JS-METACALC-2826197",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "report@snyk.io"
},
{
"url": "https://github.com/metarhia/metacalc/commit/625c23d63eabfa16fc815f5832b147b08d2144bd",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/metarhia/metacalc/pull/16",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://snyk.io/vuln/SNYK-JS-METACALC-2826197",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-94"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor."
},
{
"lang": "es",
"value": "El paquete metacalc versiones anteriores a 0.0.2, es vulnerable a una ejecución arbitraria de código cuando expone la clase Math de JavaScript al contexto v8. Como la clase Math está expuesta al contexto del usuario, puede ser usada para conseguir acceso al constructor de funciones de JavaScript"
}
],
"lastModified": "2026-06-17T04:25:33.693",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:metarhia:metacalc:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "515FDC04-65C9-4337-ADFB-BFBC356A2DE1",
"versionEndExcluding": "0.0.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "report@snyk.io"
}