Researchers disclosed an out-of-bounds heap-write flaw in the Go-based JavaScript engine Goja affecting TypedArray.prototype.with and TypedArray.prototype.toReversed. The implementations incorrectly apply a source TypedArray offset when writing to a newly allocated destination array; Goja’s use of unsafe pointer operations converts the logic error into memory corruption. Researchers built arbitrary read/write primitives and hijacked a Go function pointer associated with Date.now to achieve arbitrary code execution.
The flaw was demonstrated as post-authentication remote code execution in Zendesk Action Flows and as arbitrary code execution in ProjectDiscovery Nuclei. In Nuclei, a malicious JavaScript payload placed in a template’s init section could execute before template signature validation. Zendesk and ProjectDiscovery have issued patches; organizations running untrusted JavaScript through Goja should update to the latest patched Goja release and review JavaScript-enabled workflows and Nuclei template sources.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Zendesk and ProjectDiscovery Nuclei applied patches for the Goja vulnerability. Organizations using Goja to run untrusted JavaScript were advised to update to the latest Goja release.
Researchers showed that malicious JavaScript in a Nuclei template's init section executed before template signature validation, enabling arbitrary code execution even though Nuclei subsequently rejected the unsigned template. The proof of concept executed commands as root in the test environment, including on macOS through a ROP-based path.
Researchers demonstrated that an authenticated user able to provide malicious JavaScript to a Zendesk Action Flows custom-code step could achieve remote code execution through Goja.
The researchers reported the vulnerability to Zendesk and the Goja project in mid-June. Zendesk merged a remediation pull request within days, according to the researchers.
Researchers identified an out-of-bounds heap-write in Goja's TypedArray.prototype.with and TypedArray.prototype.toReversed methods. The flaw could be developed into arbitrary read/write primitives and Go function-pointer hijacking for arbitrary code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
reddit.com
Open sourceslcyber.io
Open sourceslcyber.io
Open sourcepkg.go.dev
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.