CRITICAL9.8
GHSA-v756-4whv-48vc
Code Injection in cd-messenger
Details
cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument executed by the `eval` function resulting in code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/cd-messenger
Introduced in:
0No fixed version published yet for cd-messenger (npm). Pin to a known-safe version or switch to an alternative.