Description
This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".
Remediation
References
https://github.com/mahdaen/node-import/blob/master/index.js%23L79
https://security.snyk.io/vuln/SNYK-JS-NODEIMPORT-571691
Related Vulnerabilities
CVE-2018-5673 Vulnerability in maven package org.dojotoolkit:dojo
CVE-2017-16057 Vulnerability in npm package nodemssql
CVE-2021-21306 Vulnerability in npm package marked
CVE-2021-22144 Vulnerability in maven package org.elasticsearch:elasticsearch
CVE-2021-39153 Vulnerability in maven package com.thoughtworks.xstream:xstream