Description
node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` located within `lib/extend.js` is executed by the `eval` function, resulting in code execution.
Remediation
References
https://snyk.io/vuln/SNYK-JS-NODEEXTEND-571491
Related Vulnerabilities
CVE-2022-41710 Vulnerability in npm package electron-markdownify
CVE-2023-4043 Vulnerability in maven package org.eclipse.parsson:project
CVE-2022-25894 Vulnerability in maven package com.bstek.uflo:uflo-core
CVE-2023-38894 Vulnerability in npm package tree-kit
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_2.13