GHSA-3jm4-c6qf-jrh3
HIGHCVE-2024-47879Lack of CSRF protection on the preview-expression command means that visiting a malicious website could cause an attacker-controlled expression to be executed. The expression can contain arbitrary Clojure or Python code.
- Affected
- < 3.8.3
- Fixed in
- 3.8.3
- Weakness
- CWE-94
- Published
- 2024-10-24
- Source
- github