-
CVSS Score
-The vulnerability stems from improper scope management when a nested function is declared in a parameter scope. The commit fixes incorrect envIndex calculations by adjusting how parameter scope instantiation is handled. The key vulnerable functions are:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| Microsoft.ChakraCore | nuget | < 1.11.19 | 1.11.19 |
Ongoing coverage of React2Shell