VDB
Sign up
CRITICAL10.0

GHSA-79xf-67r4-q2jj

safe-eval vulnerable to Sandbox Bypass due to improper input sanitization

Details

All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerability is derived from prototype pollution exploitation. Exploiting this vulnerability might result in remote code execution (RCE).

**Vulnerable functions:**

__defineGetter__, stack(), toLocaleString(), propertyIsEnumerable.call(), valueOf().

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/safe-eval
Introduced in: 0

No fixed version published yet for safe-eval (npm). Pin to a known-safe version or switch to an alternative.

References