CVE-2024-40453(squirrelly / squirrelly)

LOWCVSS 9.8 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • squirrelly

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Affected systems

Vendors
Products
squirrelly

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-10-07: 310-07
Referenced assets1 URL
By indicator
Full discourse3 posts
  • ExploitGrid@exploitgrid

    ExploitGrid Daily Digest 🚨 Top Exploits: CVE-2025-57819 (CVSS: 10) FreePBX CVE-2026-105134 (CVSS: 10) Ahsay CVE-2026-40281 (CVSS: 10) gotenberg CVE-2024-40453 (CVSS: 9.8) CVE-2026-39987 (CVSS: 9.3) marimo-team ..🧵👇

    11061289
    370 followersView on X
  • ExploitGrid@exploitgrid

    💀 CRITICAL Exploits Trending ├ CVE-2025-57819 — FreePBX ("FreePBX-Breaker") · PoC live ├ CVE-2026-105134 — Ahsay · PoC live ├ CVE-2026-40281 (Gotenberg) · still unpatched, PoC live again ├ CVE-2024-40453 · PoC live (9.8) └ CVE-2026-39987 — marimo · RCE PoC live (9.3)

    1000034
    370 followersView on X
  • ExploitGrid@exploitgrid

    [EXPLOIT] CVE-2024-40453 [CRITICAL/PoC] CVSS: 9.8 CVE-2024-40453 🔗 https://exploitgrid.net/exploits/0a14b1a2-b9a9-4b29-90f7-db209ad8bb37

    1000049
    370 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsquirrellysquirrelly9.0.0node.js-

Explore more