Description
safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SAFEREVAL-173772
Related Vulnerabilities
CVE-2023-26480 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livedata-macro
CVE-2023-46233 Vulnerability in maven package org.webjars.npm:crypto-js
CVE-2021-43786 Vulnerability in npm package nodebb
CVE-2022-24823 Vulnerability in maven package io.netty:netty-codec-http
CVE-2022-24615 Vulnerability in maven package net.lingala.zip4j:zip4j