{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/faker--10.4.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:fakerjs:faker:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-73231"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["faker (\u003c= 10.4.0)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","javascript"],"_cs_type":"advisory","_cs_vendors":["Faker.js"],"content_html":"\u003cp\u003eFaker.js versions 10.4.0 and earlier are vulnerable to an arbitrary code execution flaw within the \u003ccode\u003ehelpers.fake\u003c/code\u003e method, tracked as CVE-2026-73231. The vulnerability exists due to improper property resolution logic in \u003ccode\u003efakeEval.resolveProperty\u003c/code\u003e. Specifically, the function attempts to resolve properties on functions directly rather than performing a recursive resolution. This logic error allows attackers to traverse and access the \u003ccode\u003econstructor\u003c/code\u003e of objects, providing a path to execute arbitrary JavaScript code.\u003c/p\u003e\n\u003cp\u003eThe library documentation explicitly claims that it is not possible to use non-faker methods or plain JavaScript within fake template strings; however, this vulnerability proves that global objects remain accessible. An attacker can craft a template string containing a payload such as \u003ccode\u003e{{test.constructor(alert('Code Execution'))}}\u003c/code\u003e to escape the intended sandbox. This impacts any application that processes user-supplied or untrusted strings through the \u003ccode\u003ehelpers.fake\u003c/code\u003e function.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for remote code execution in any environment where an attacker can influence the template string passed to the \u003ccode\u003ehelpers.fake\u003c/code\u003e method. This affects all applications leveraging Faker.js versions 10.4.0 and below. If an application uses this method to process inputs from end-users or external sources, an attacker could achieve full code execution within the Node.js or browser environment, potentially leading to data exfiltration or unauthorized system access.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003e@faker-js/faker\u003c/code\u003e package to a version beyond 10.4.0 immediately to resolve CVE-2026-73231.\u003c/li\u003e\n\u003cli\u003eAudit all application codebases for instances where user-supplied or external input is passed directly into the \u003ccode\u003efaker.helpers.fake\u003c/code\u003e method.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately feasible, sanitize all input strings passed to \u003ccode\u003ehelpers.fake\u003c/code\u003e to block characters and patterns that could facilitate access to the \u003ccode\u003econstructor\u003c/code\u003e property or other global objects.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T18:06:25Z","date_published":"2026-09-02T18:06:25Z","id":"https://feed.craftedsignal.io/briefs/2026-09-faker-rce/","summary":"The Faker.js library contains an arbitrary code execution vulnerability in the helpers.fake method, allowing attackers to access the global constructor and execute unauthorized JavaScript.","title":"Arbitrary Code Execution in Faker.js helpers.fake","url":"https://feed.craftedsignal.io/briefs/2026-09-faker-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Faker (\u003c= 10.4.0)","version":"https://jsonfeed.org/version/1.1"}