Description
cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument executed by the `eval` function resulting in code execution.
Remediation
References
https://snyk.io/vuln/SNYK-JS-CDMESSENGER-571493
Related Vulnerabilities
CVE-2010-2076 Vulnerability in maven package org.apache.cxf:cxf-bundle-jaxrs
CVE-2023-24163 Vulnerability in maven package cn.hutool:hutool-all
CVE-2023-2507 Vulnerability in npm package clevertap-cordova
CVE-2021-23436 Vulnerability in npm package immer
CVE-2023-26487 Vulnerability in maven package org.webjars.npm:vega