Executive brief
total4 is a Node.js framework package used for building web applications. The U.set() and U.get() utility functions in versions before 0.0.43 allow attackers to inject and execute arbitrary code, potentially compromising application availability, data integrity, and confidentiality. An attacker who can influence input to these functions can achieve complete system takeover without authentication.
Technical details
The vulnerability is a code injection flaw (CWE-94) in the total4 npm package, specifically in the U.set() and U.get() utility functions, which fail to properly sanitize or restrict code execution. These functions allow arbitrary code execution when processing attacker-controlled input. The attack vector is network-based with no authentication or user interaction required. An attacker with access to the application (either direct or indirect) can execute arbitrary code in the context of the Node.js process. The vulnerability was fixed in version 0.0.43, which removed the vulnerable methods entirely (commit 8a72d8c).
Affected products
- total.js total4 before 0.0.43
Timeline
- 2021-07-12: disclosed
- 2021-06-04: patched: Vulnerable methods U.set(), U.get(), U.sync(), U.sync2() removed in version 0.0.43
- 2021-12-10: advisory: GHSA-g7mq-rfj2-25wq published