Less.js Untrusted File Compilation / Code Execution

RedTeam Pentesting discovered behavior in the Less.js compiler, which allows execution of arbitrary code if an untrusted LESS file is compiled.

Leave a Reply