Description
In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.
Remediation
References
https://github.com/mysticatea/eslint-utils/security/advisories/GHSA-3gx7-xhv7-5mx3
Related Vulnerabilities
CVE-2018-3721 Vulnerability in npm package @sailshq/lodash
CVE-2022-43426 Vulnerability in maven package io.jenkins.plugins:s3explorer
CVE-2022-39236 Vulnerability in npm package matrix-js-sdk
CVE-2019-8331 Vulnerability in maven package org.webjars:bootstrap
CVE-2021-26296 Vulnerability in maven package org.apache.myfaces.core:myfaces-core-project