VDB
Sign up
HIGH8.6

GHSA-j665-rvj7-2jv9

Code Injection in mosc

Details

mosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to `properties` argument is executed by the `eval` function, resulting in code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mosc
Introduced in: 0

No fixed version published yet for mosc (npm). Pin to a known-safe version or switch to an alternative.

References