Description
This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".
Remediation
References
https://github.com/mahdaen/node-import/blob/master/index.js%23L79
https://security.snyk.io/vuln/SNYK-JS-NODEIMPORT-571691
Related Vulnerabilities
CVE-2018-3722 Vulnerability in npm package merge-deep
CVE-2022-2596 Vulnerability in npm package node-fetch
CVE-2023-3224 Vulnerability in npm package nuxt
CVE-2020-28500 Vulnerability in maven package org.webjars.bower:lodash
CVE-2021-42697 Vulnerability in maven package com.typesafe.akka:akka-http_2.13