Safe-eval Project
Safe-eval Project Safe-eval: vulnerabilidades y CVE
Safe-eval Project Safe-eval tiene 5 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 5 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE5
Últimos 12 meses0
Críticas5
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-26122 | Crítica (10) | 2.1% | — | 11 abr 2023 | All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerability is derived from prototype pollution exploitation. Exploiting this vulnerability might result… |
| CVE-2023-26121 | Crítica (10) | 1.1% | — | 11 abr 2023 | All versions of the package safe-eval are vulnerable to Prototype Pollution via the safeEval function, due to improper sanitization of its parameter content. |
| CVE-2022-25904 | Crítica (9.8) | 0.88% | — | 20 dic 2022 | All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify properties of the Object.prototype.Consolidate when using the function safeEval. This is because the… |
| CVE-2020-7710 | Crítica (9.8) | 1.4% | — | 21 ago 2020 | This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine. |
| CVE-2017-16088 | Crítica (10) | 3.5% | — | 7 jun 2018 | The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox. |