Arbitrary Code Execution Vulnerability in Meta Spark Studio by Facebook
CVE-2024-23347
7.8HIGH
What is CVE-2024-23347?
Meta Spark Studio, a product developed by Facebook, has a vulnerability that allows the execution of arbitrary code. Prior to version 176, when a new project is opened, the application would automatically execute scripts defined within the package.json file included in the project directory. This behavior could be exploited by a malicious actor, enabling them to run arbitrary code with the same permissions as the application on the host system, potentially leading to a compromise of the system integrity and security.
Affected Version(s)
Meta Spark Studio 0 < 176