Description
safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SAFEREVAL-173772
Related Vulnerabilities
CVE-2016-10540 Vulnerability in npm package minimatch
CVE-2022-45208 Vulnerability in maven package org.jeecgframework.boot:jeecg-module-system
CVE-2020-28271 Vulnerability in npm package deephas
CVE-2020-26238 Vulnerability in maven package com.cronutils:cron-utils
CVE-2023-46131 Vulnerability in maven package org.grails:grails-databinding