Description
safer-eval before 1.3.2 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SAFEREVAL-473029
Related Vulnerabilities
CVE-2020-36048 Vulnerability in npm package engine.io
CVE-2019-14862 Vulnerability in maven package li.rudin.mavenjs:knockout
CVE-2021-34083 Vulnerability in npm package google-it
CVE-2022-23622 Vulnerability in maven package org.xwiki.platform:xwiki-platform-web-templates
CVE-2022-25869 Vulnerability in maven package org.webjars.npm:angular