GHSA-vh2g-6c4x-5hmp
CRITICALCVE-2023-26045Due to the use of the [object destructuring assignment](https://developer.mozilla.org/en-US/docs/Web/JavaScript/Reference/Operators/Destructuringassignment) syntax in the user export code path, combined with a path traversal vulnerability, a specially crafted payload could invoke the user export logic to arbitrarily execute javascript files on the local disk.
- Affected
- >= 2.5.0, < 2.8.7
- Fixed in
- 2.8.7
- Weakness
- CWE-22
- Published
- 2023-07-25
- Source
- github