Description
The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.
Remediation
References
https://github.com/substack/static-eval/pull/18
https://maustin.net/articles/2017-10/static_eval
https://nodesecurity.io/advisories/548
Related Vulnerabilities
CVE-2020-26296 Vulnerability in maven package org.webjars.bowergithub.vega:vega
CVE-2020-5263 Vulnerability in npm package auth0-js
CVE-2020-36640 Vulnerability in maven package org.bonitasoft.connectors:bonita-connector-webservice
CVE-2022-24717 Vulnerability in npm package @finastra/ssr-pages
CVE-2013-4204 Vulnerability in maven package com.google.gwt:gwt-user