peter bassill · operator
$ cve CVE-2024-28397 JSON

CVE-2024-28397 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 4.5% (pctl 91)

Patch early

A public exploit exists.

Description

An issue in the component js2py.disable_pyimport() of js2py up to v0.74 allows attackers to execute arbitrary code via a crafted API call.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS4.55% — more likely to be exploited than 91% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2024-06-20
Last modified2026-06-17

Public exploits

SourceTitleDate
exploit-dbJs2Py 0.74 - RCE2026-04-30

References

→ the Explorer  ·  watch your stack  ·  NVD