VDB
Sign up
CRITICAL9.8

GHSA-cg42-4wrc-gp47

Code Injection in node-extend

Details

node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` located within `lib/extend.js` is executed by the `eval` function, resulting in code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/node-extend
Introduced in: 0

No fixed version published yet for node-extend (npm). Pin to a known-safe version or switch to an alternative.

References