Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q9v2-7m5w-4693

Опубликовано: 23 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.2
CVSS3: 9.8

Описание

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.

EPSS

Процентиль: 40%
0.00496
Низкий

9.2 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 4.2
redhat
около 2 месяцев назад

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.

CVSS3: 9.8
nvd
около 2 месяцев назад

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by supplying crafted expressions that are compiled into native code using new Function(). Because user-controlled expressions are transformed directly into executable JavaScript, attackers can escape the intended expression sandbox and run arbitrary code within the application's context.

EPSS

Процентиль: 40%
0.00496
Низкий

9.2 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-94