VDB
Sign up
HIGH8.6

GHSA-pgjj-866w-fc5c

Risk of code injection

Details

### Impact Some routes use `eval` or `Function constructor`, which may be injected by the target site with unsafe code, causing server-side security issues

### Patches Temporarily removed the problematic route and added a `no-new-func` rule to eslint Self-built users should upgrade to 7f1c430 and later as soon as possible

### Credits Tencent Woodpecker Security Team

### For more information If you have any questions or comments about this advisory: * Open an issue in [https://github.com/DIYgod/RSSHub/issues](https://github.com/DIYgod/RSSHub/issues) * Email us at [i@diygod.me](mailto:i@diygod.me)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/rsshub
Introduced in: 0

No fixed version published yet for rsshub (npm). Pin to a known-safe version or switch to an alternative.

References