VDB
Sign up
CRITICAL10.0

GHSA-hcg3-56jf-x4vh

safe-eval vulnerable to Prototype Pollution via the safeEval function

Details

All versions of the package safe-eval are vulnerable to Prototype Pollution via the safeEval function, due to improper sanitization of its parameter content.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/safe-eval
Introduced in: 0

No fixed version published yet for safe-eval (npm). Pin to a known-safe version or switch to an alternative.

References