CVE-2023-46308 | plotly.js up to 2.25.1 API Call expandObjectPaths/nestedProperty code injection (EUVD-2024-0449)
A vulnerability has been found in plotly.js up to 2.25.1 and classified as critical. This affects the function expandObjectPaths/nestedProperty of the component API Call Handler. The manipulation leads to code injection.
This vulnerability is documented as CVE-2023-46308. The attack requires being on the local network. There is not any exploit available.
The affected component should be upgraded.