Description
This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine.
Remediation
References
https://github.com/hacksparrow/safe-eval/issues/19
https://snyk.io/vuln/SNYK-JS-SAFEEVAL-608076
Related Vulnerabilities
CVE-2023-37263 Vulnerability in npm package @strapi/plugin-content-manager
CVE-2020-1912 Vulnerability in npm package hermes-engine
CVE-2020-14967 Vulnerability in npm package jsrsasign
CVE-2022-36437 Vulnerability in maven package com.hazelcast.jet:hazelcast-jet
CVE-2023-39154 Vulnerability in maven package com.qualys.plugins:qualys-was