Description
cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument executed by the `eval` function resulting in code execution.
Remediation
References
https://snyk.io/vuln/SNYK-JS-CDMESSENGER-571493
Related Vulnerabilities
CVE-2021-44228 Vulnerability in maven package org.apache.logging.log4j:log4j-core
CVE-2021-21290 Vulnerability in maven package io.netty:netty-transport-native-unix-common-tests
CVE-2022-41376 Vulnerability in npm package metro4
CVE-2021-26118 Vulnerability in maven package org.apache.activemq:artemis-openwire-protocol