VDB
Sign up
CRITICAL9.8

GHSA-3gx7-xhv7-5mx3

Arbitrary Code Execution in eslint-utils

Quick fix

GHSA-3gx7-xhv7-5mx3 — eslint-utils: upgrade to the fixed version with the command below.

npm install eslint-utils@1.4.1

Details

Versions of `eslint-utils` >=1.2.0 or <1.4.1 are vulnerable to Arbitrary Code Execution. The `getStaticValue` does not properly sanitize user input allowing attackers to supply malicious input that executes arbitrary code during the linting process. The `getStringIfConstant` and `getPropertyName` functions are not affected.

## Recommendation

Upgrade to version 1.4.1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/eslint-utils
Introduced in: 1.2.0Fixed in: 1.4.1
Fixnpm install eslint-utils@1.4.1

References