VDB
Sign up
CRITICAL9.8

GHSA-v756-4whv-48vc

Code Injection in cd-messenger

Details

cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument executed by the `eval` function resulting in code execution.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/cd-messenger
Introduced in: 0

No fixed version published yet for cd-messenger (npm). Pin to a known-safe version or switch to an alternative.

References