Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
CVE-2022-23529 – node-jsonwebtoken (nist.gov)
2 points by robin_reala on Jan 10, 2023 | hide | past | favorite | 3 comments


If this is a CVE, then arguably any method invocation on any function argument in any JavaScript library is a CVE, and we might as well throw the whole thing away. Is there a way to challenge this as not-a-CVE?



This CVE is a joke, there is no attack vector. If an attacker is able to create an object with an executable function in the scope claimed in the CVE, he may just run the malicious code himself.




Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: