VDB
Sign up
HIGH

GHSA-jc85-fpwf-qm7x

expr-eval does not restrict functions passed to the evaluate function

Quick fix

GHSA-jc85-fpwf-qm7x — expr-eval-fork: upgrade to the fixed version with the command below.

npm install expr-eval-fork@3.0.1

Details

The expr-eval library is a JavaScript expression parser and evaluator designed to safely evaluate mathematical expressions with user-defined variables. However, due to insufficient input validation, an attacker can pass a crafted variables object into the evaluate() function and trigger arbitrary code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/expr-eval
Introduced in: 0

No fixed version published yet for expr-eval (npm). Pin to a known-safe version or switch to an alternative.

npm/expr-eval-fork
Introduced in: 0Fixed in: 3.0.1
Fixnpm install expr-eval-fork@3.0.1

References