Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: Critical Vulnerability Found in Popular Python Library
Newsletter
Newsletter →
HackerDose
HackerDose
  • Latest Stories
  • Security & Tech
    • Cybersecurity
    • Technology
    • Vulnerabilities
    • Dark Web
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
Reading: Critical Vulnerability Found in Popular Python Library
Newsletter
Search
  • Latest Stories
  • Security & Tech
    • Security
    • Vulnerabilities
    • Dark Web
    • Technology
    • Privacy
  • Crypto & Blockchain
    • Cryptocurrency
    • Blockchain
    • Finance
    • Price Predictions
    • Guides
    • Regulation
© MRS Media Company. Hackerdose LLC. All Rights Reserved.

Vulnerabilities » Critical Vulnerability Found in Popular Python Library

Vulnerabilities

Critical Vulnerability Found in Popular Python Library

The widely-used Python library js2py has been discovered to contain a critical vulnerability, CVE-2024-28397, which has the potential to expose numerous web scrapers and applications to remote code execution attacks.

Marco Rizal
Last updated: August 21, 2024 10:20 am
By Marco Rizal - Editor, Journalist 3 Min Read
Share
Flaw Found In Js2Py
SHARE

A major vulnerability has been identified in the widely used Python library js2py. This library is utilized by numerous web scrapers and applications, and it receives more than one million monthly downloads.

The vulnerability, identified as CVE-2024-28397, is of the highest severity and enables malicious actors to execute any commands they desire on a system through the use of js2py.

In February, Marven11, a security researcher, identified the issue. He promptly submitted a patch  to the official js2py repository. Marven11 elected to inform the public of the issue and the solution.

After four months of silence from the project maintainers, Marven11 has decided to go public with both the proof-of-concept exploit and the fix.

js2py is a favored tool among Python developers due to its ability to integrate JavaScript into their applications.

It is favored by numerous web scraping tools due to its ability to receive and execute JavaScript from web pages.

However, this attribute is currently hazardous. It is possible for malicious actors to deceive an individual into executing a JavaScript file that is harmful.

This can be accomplished by means of a fabricated API call or a compromised website. The perpetrator has the ability to assume control of the host system and execute any command they desire when the harmful script is executed.

The vulnerability is present in all versions of js2py, including version 0.74, when they are operating under Python versions below 3.12.

Additionally, the utilization of js2py poses a threat to numerous prominent projects, including pyload, cloudscraper, and lightnovel-crawler.

At present, the js2py maintainers have not issued an official patch. However, the modification implemented by Marven11 is accessible to users.

They can accomplish this by manually altering the source code in accordance with the instructions in patch.txt or by employing a fix.py script.

Developers and administrators should promptly update or resolve any applications that utilize js2py due to the severity of this issue. Remote code execution attacks pose an overwhelming danger that cannot be disregarded.

Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Subscribe to our newsletter

Receive the latest news and stories straight to your inbox.

Latest stories

Bitcoin Holds at $85K as Global Trade Tensions and Fed Speculation Unfold

April 15, 2025

Michael Saylor Doubles Down on Bitcoin (BTC) with $285M Investment Amid Global Uncertainty

April 14, 2025

Mantra Faces Crisis After OM Token Crashes 90% in a Day

April 14, 2025

Solana (SOL) on the Verge of a Breakout: Could $300 Be the Next Target?

April 14, 2025

You might also like

Backdoor in AI Models Waiting to Strike

Sleeping Backdoor in AI Models Waiting to Strike

Hugging Face Chat Platform Vulnerabilities Exposed in New Security Research

Hugging Face Chat Platform Vulnerabilities Exposed in New Security Research

CocoaPods Vulnerabilities from 2014 Endanger Millions of Apple Devices

CocoaPods Vulnerabilities from 2014 Endanger Millions of Apple Devices

Bitcoins DoS Vulnerability

Bitcoin’s DoS Vulnerability Lets Hackers Crash Miners For Less Than 1% of a Block

Newsletter

Our website stores cookies on your computer. They allow us to remember you and help personalize your experience with our site

Quick Links

  • Contact Us
  • Search
  • Malware
  • Downloads

Company

  • About Us
  • Terms and Conditions
  • Cookies Policy
  • Privacy Policy
Advertise with us

Socials

Follow Us

© 2025 | HackerDose Media Company – All Rights Reserved

Welcome Back!

Sign in to your account

Lost your password?