CRITICAL9.8
GHSA-cg42-4wrc-gp47
Code Injection in node-extend
Details
node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` located within `lib/extend.js` is executed by the `eval` function, resulting in code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/node-extend
Introduced in:
0No fixed version published yet for node-extend (npm). Pin to a known-safe version or switch to an alternative.