Description
This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine.
Remediation
References
https://github.com/hacksparrow/safe-eval/issues/19
https://snyk.io/vuln/SNYK-JS-SAFEEVAL-608076
Related Vulnerabilities
CVE-2022-35131 Vulnerability in npm package joplin
CVE-2020-15270 Vulnerability in npm package parse-server
CVE-2020-7642 Vulnerability in maven package org.webjars.bower:lazysizes
CVE-2022-0512 Vulnerability in npm package url-parse
CVE-2022-22947 Vulnerability in maven package org.springframework.cloud:spring-cloud-gateway