GHSA-gmpm-xp43-f7g6
Dashboard / Vulnerabilities / GHSA-gmpm-xp43-f7g6
Summary: Signed to Unsigned Conversion Error in Facebook Hermes
Details: An Integer signedness error in the JavaScript Interpreter in Facebook Hermes prior to commit 2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6 allows attackers to cause a denial of service attack or a potential RCE via crafted JavaScript. Note that this is only exploitable if the application using Hermes permits evaluation of untrusted JavaScript. Hence, most React Native applications are not affected.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-1913, https://github.com/facebook/hermes/commit/2c7af7ec481ceffd0d14ce2d7c045e475fd71dc6, https://www.facebook.com/security/advisories/cve-2020-1913
Affected packages
Package
Name: hermes-engine
Purl: pkg:npm/hermes-engine
Affected ranges
Type: SEMVER
Events:
