CVE-2018-6333 describes a critical vulnerability in Facebook Nuclide versions prior to v0.290.0, where the hhvm-attach deep link handler failed to sanitize the hostname parameter. This allowed for malicious URLs to inject HTML and other content within the editor's context, potentially leading to remote code execution. With a CVSS score of 9.8 (CRITICAL) and an attack vector of Network with low complexity, the potential impact includes complete compromise of confidentiality, integrity, and availability. While there are no known public exploits or Metasploit modules, the vulnerability has garnered some community discussion and media coverage, indicating awareness despite no active exploitation reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.290.0CPE matchmatch criteria | cpe:2.3:a:facebook:nuclide:*:*:*:*:*:*:*:* | ||
<= v0.290.0CPE match | cpe:2.3:a:facebook:nuclide:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.