Vulnerability record · CVE-2014-7205 · published 8 October 2014
CVE-2014-7205: Bassmaster hapi plugin eval injection allows remote code execution
Bassmaster Project · Bassmaster
The internals.batch function in lib/batch.js of the bassmaster plugin for the hapi Node.js framework evaluates attacker-supplied input, allowing arbitrary JavaScript execution. The flaw affects bassmaster versions before 1.5.2 and is remotely reachable without authentication, making it a full compromise risk for exposed servers.
Description
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10 and very high EPSS probability, though no KEV listing.
What it is
The internals.batch function in lib/batch.js of the bassmaster plugin for the hapi Node.js framework evaluates attacker-supplied input, allowing arbitrary JavaScript execution. The flaw affects bassmaster versions before 1.5.2 and is remotely reachable without authentication, making it a full compromise risk for exposed servers.
Impact
An unauthenticated remote attacker can execute arbitrary JavaScript in the Node.js process, leading to full confidentiality, integrity and availability loss on the host.
Attack surface
Reached over the network through the plugin's batch endpoint; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.786, 99.6th percentile) and references include an Exploit-tagged commit and an Exploit-DB entry, indicating public exploit material exists.
What to do
- Upgrade bassmaster to version 1.5.2 or later, which contains the fix commit b751602d8cb7194ee62a61e085069679525138c4.
- If upgrade is not possible, disable or remove the bassmaster plugin from hapi servers.
- Restrict network access to the batch endpoint to trusted clients only.
- Run the Node.js service with least privilege and isolate it from sensitive internal systems.
Detection
- Monitor application and server logs for requests to the bassmaster batch endpoint containing JavaScript-like payloads.
- Alert on unexpected child_process, eval, or Function usage in Node.js process telemetry.
- Watch for outbound connections or process spawning from the Node.js service that deviate from baseline behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.openwall.com/lists/oss-security/2014/09/30/10 | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/70180 | Third Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/96730 | Third Party AdvisoryVDB Entry |
| https://github.com/hapijs/bassmaster/commit/b751602d8cb7194ee62a61e085069679525138c4 | Exploit |
| https://nodesecurity.io/advisories/bassmaster_js_injection | Third Party Advisory |
| https://www.exploit-db.com/exploits/40689/ | Third Party AdvisoryVDB Entry |
| http://www.openwall.com/lists/oss-security/2014/09/30/10 | Mailing ListThird Party Advisory |
| http://www.securityfocus.com/bid/70180 | Third Party AdvisoryVDB Entry |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/96730 | Third Party AdvisoryVDB Entry |
| https://github.com/hapijs/bassmaster/commit/b751602d8cb7194ee62a61e085069679525138c4 | Exploit |
| https://nodesecurity.io/advisories/bassmaster_js_injection | Third Party Advisory |
| https://www.exploit-db.com/exploits/40689/ | Third Party AdvisoryVDB Entry |
Track CVE-2014-7205 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2014-7205), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.