← Vulnerability feed

Vulnerability record · CVE-2014-7205 · published 8 October 2014

CVE-2014-7205: Bassmaster hapi plugin eval injection allows remote code execution

Bassmaster Project · Bassmaster

The internals.batch function in lib/batch.js of the bassmaster plugin for the hapi Node.js framework evaluates attacker-supplied input, allowing arbitrary JavaScript execution. The flaw affects bassmaster versions before 1.5.2 and is remotely reachable without authentication, making it a full compromise risk for exposed servers.

10.0 CVSS 2.0 High EPSS 79% · top 0.4% CWE-94 · Code injection
10.0CVSS 2.0 base score
79%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote code execution with a CVSS 2.0 score of 10 and very high EPSS probability, though no KEV listing.

What it is

The internals.batch function in lib/batch.js of the bassmaster plugin for the hapi Node.js framework evaluates attacker-supplied input, allowing arbitrary JavaScript execution. The flaw affects bassmaster versions before 1.5.2 and is remotely reachable without authentication, making it a full compromise risk for exposed servers.

Impact

An unauthenticated remote attacker can execute arbitrary JavaScript in the Node.js process, leading to full confidentiality, integrity and availability loss on the host.

Attack surface

Reached over the network through the plugin's batch endpoint; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is very high (0.786, 99.6th percentile) and references include an Exploit-tagged commit and an Exploit-DB entry, indicating public exploit material exists.

What to do

  • Upgrade bassmaster to version 1.5.2 or later, which contains the fix commit b751602d8cb7194ee62a61e085069679525138c4.
  • If upgrade is not possible, disable or remove the bassmaster plugin from hapi servers.
  • Restrict network access to the batch endpoint to trusted clients only.
  • Run the Node.js service with least privilege and isolate it from sensitive internal systems.

Detection

  • Monitor application and server logs for requests to the bassmaster batch endpoint containing JavaScript-like payloads.
  • Alert on unexpected child_process, eval, or Function usage in Node.js process telemetry.
  • Watch for outbound connections or process spawning from the Node.js service that deviate from baseline behavior.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2014-7205 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-65660Microsoft sharepoint server code injection vulnerabilityImproper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.KEVEPSS 2.1%9.8CVE-2026-60004Gitea diffpatch API code injection enables remote code executionGitea before 1.27.1 allows remote code execution through the diffpatch API by way of Git hook installation. The flaw is a code injection issue (CWE-9…KEVEPSS 24%analysed9.5CVE-2026-72530TrueConf Server sandbox breakout via crafted script code injectionTrueConf Server versions 5.3.X through 5.3.9, 5.4.X through 5.4.9, 5.5.X through 5.5.5 and earlier allow a remote unauthenticated attacker to break o…KEVEPSS 1.7%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed9.8CVE-2026-9198Langflow auto_login and code validation chain enables unauthenticated RCEIBM Langflow OSS 1.0.0 through 1.10.0 exposes /api/v1/auto_login, which mints SUPERUSER tokens to any network caller, and /api/v1/validate/code, whic…KEVEPSS 29%analysed7.2CVE-2026-15410SonicWall SMA1000 AMC code injection allows OS command executionThe SMA1000 Appliance Management Console (AMC) contains a post-authentication code injection flaw (CWE-94) that, under specific conditions, lets an a…KEVEPSS 12%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2026-34197Apache ActiveMQ Jolokia JMX bridge code injection via broker config URIApache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ with a default policy that allows exec operations on all org.apache.acti…KEVEPSS 15%analysed

Source: NIST National Vulnerability Database (record CVE-2014-7205), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.