THREAT OPS › Threat News › [GHSA] GHSA-qxc2-j82w-r537 (high) — Faker: helpers.fake exploitable into arbritary code execution
[GHSA] GHSA-qxc2-j82w-r537 (high) — Faker: helpers.fake exploitable into arbritary code execution
GHSA-qxc2-j82w-r537 Severity: high CVE: CVE-2026-73231
Faker: helpers.fake exploitable into arbritary code execution
### Summary
`faker.helpers.fake` can be tricked into arbritary code execution.
### Details
fakeEval.resolveProperty resolves properties on functions itself instead of resolving the nested function first. This can be addressed by recursively calling resolveProperty instead of ac
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-73231cve
- https://fakerjs.dev/url
Original source: https://github.com/advisories/GHSA-qxc2-j82w-r537