Description
This affects all versions of package node-import. The "params" argument of module function can be controlled by users without any sanitization.b. This is then provided to the “eval” function located in line 79 in the index file "index.js".
Remediation
References
https://github.com/mahdaen/node-import/blob/master/index.js%23L79
https://security.snyk.io/vuln/SNYK-JS-NODEIMPORT-571691
Related Vulnerabilities
CVE-2017-16185 Vulnerability in npm package uekw1511server
CVE-2023-26107 Vulnerability in npm package sketchsvg
CVE-2017-7682 Vulnerability in maven package org.apache.openmeetings:openmeetings-web
CVE-2020-8910 Vulnerability in npm package google-closure-library
CVE-2015-8854 Vulnerability in maven package org.webjars.npm:marked