Safer-eval ProjectCVEs & Vulnerabilities
3 CVEs affecting Safer-eval Project products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.
3 CVEs→ All vendors
Most Affected Products
safer-eval 3
CVE-2019-10769CRITICAL
safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are vulnerable to Arbitrary Code Execution via generating a RangeError.
7 Dec 2019
9.8
CVSS
CVE-2019-10760CRITICAL
safer-eval before 1.3.2 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.
15 Oct 2019
9.9
CVSS
CVE-2019-10759CRITICAL
safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.
15 Oct 2019
9.9
CVSS
← PrevPage 1 / 1Next →