Description
safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SAFEREVAL-173772
Related Vulnerabilities
CVE-2023-36665 Vulnerability in maven package org.webjars.npm:protobufjs
CVE-2023-34238 Vulnerability in npm package gatsby-transformer-remark
CVE-2018-3729 Vulnerability in npm package localhost-now
CVE-2022-24814 Vulnerability in npm package directus
CVE-2022-38180 Vulnerability in maven package io.ktor:ktor-client-core