VDB
Sign up
HIGH7.3

GHSA-8gw3-rxh4-v6jx

expr-eval vulnerable to Prototype Pollution

Quick fix

GHSA-8gw3-rxh4-v6jx — expr-eval-fork: upgrade to the fixed version with the command below.

npm install expr-eval-fork@2.0.2

Details

npm package `expr-eval` is vulnerable to Prototype Pollution. An attacker with access to express eval interface can use JavaScript prototype-based inheritance model to achieve arbitrary code execution. The npm expr-eval-fork package resolves this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/expr-eval
Introduced in: 0

No fixed version published yet for expr-eval (npm). Pin to a known-safe version or switch to an alternative.

npm/expr-eval-fork
Introduced in: 0Fixed in: 2.0.2
Fixnpm install expr-eval-fork@2.0.2

References