Description
safer-eval before 1.3.2 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.
Remediation
References
https://snyk.io/vuln/SNYK-JS-SAFEREVAL-473029
Related Vulnerabilities
CVE-2020-28436 Vulnerability in npm package google-cloudstorage-commands
CVE-2020-25649 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2021-23337 Vulnerability in npm package lodash
CVE-2020-28453 Vulnerability in npm package npos-tesseract
CVE-2022-25867 Vulnerability in maven package io.socket:socket.io-client