All versions of the package safe-eval are vulnerable to Prototype Pollution via the safeEval function, due to improper sanitization of its parameter content.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HSafe Eval Project Safe Eval
APPSafe-Eval Project≤ 0.4.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
References
Related vulnerabilities
CVE-2017-16088CRITICAL10.0PL ✓same product
Ucieczka z sandbox w module safe-eval (Node.js) — pełny dostęp do środowiska
CVE-2023-26122HIGH8.8same product
All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The...
CVE-2022-25904HIGH7.5same product
All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or mod...
CVE-2020-7710HIGH8.1same product
This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on ...