Description
safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SAFEREVAL-173772
Related Vulnerabilities
CVE-2022-25921 Vulnerability in npm package morgan-json
CVE-2022-0613 Vulnerability in npm package urijs
CVE-2017-12617 Vulnerability in maven package org.apache.tomcat:tomcat-catalina
CVE-2022-36896 Vulnerability in maven package com.compuware.jenkins:compuware-scm-downloader
CVE-2018-6464 Vulnerability in maven package org.webjars.bower:simditor