Description
In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.
Remediation
References
https://github.com/mysticatea/eslint-utils/security/advisories/GHSA-3gx7-xhv7-5mx3
Related Vulnerabilities
CVE-2019-18394 Vulnerability in maven package org.igniterealtime.openfire:parent
CVE-2021-25948 Vulnerability in npm package expand-hash
CVE-2020-35728 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-8175 Vulnerability in maven package org.webjars.npm:jpeg-js
CVE-2021-23326 Vulnerability in npm package @graphql-tools/git-loader