GHSA-pgjj-866w-fc5c
Risk of code injection
Details
### Impact Some routes use `eval` or `Function constructor`, which may be injected by the target site with unsafe code, causing server-side security issues
### Patches Temporarily removed the problematic route and added a `no-new-func` rule to eslint Self-built users should upgrade to 7f1c430 and later as soon as possible
### Credits Tencent Woodpecker Security Team
### For more information If you have any questions or comments about this advisory: * Open an issue in [https://github.com/DIYgod/RSSHub/issues](https://github.com/DIYgod/RSSHub/issues) * Email us at [i@diygod.me](mailto:i@diygod.me)
Are you affected?
Enter the version of the package you're using.
Affected packages
0No fixed version published yet for rsshub (npm). Pin to a known-safe version or switch to an alternative.
References
- https://github.com/DIYgod/RSSHub/security/advisories/GHSA-pgjj-866w-fc5c[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2021-21278[ADVISORY]
- https://github.com/DIYgod/RSSHub/commit/7f1c43094e8a82e4d8f036ff7d42568fed00699d[WEB]
- https://github.com/DIYgod/RSSHub[PACKAGE]
- https://www.npmjs.com/package/rsshub[WEB]