High severity8.6NVD Advisory· Published Jan 26, 2021· Updated Jun 17, 2026
CVE-2021-21278
CVE-2021-21278
Description
RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk of code injection. Some routes use eval or Function constructor, which may be injected by the target site with unsafe code, causing server-side security issues The fix in version 7f1c430 is to temporarily remove the problematic route and added a no-new-func rule to eslint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
rsshubnpm | <= 1.0.0 | — |
Affected products
3Patches
Vulnerability mechanics
References
5- github.com/DIYgod/RSSHub/commit/7f1c43094e8a82e4d8f036ff7d42568fed00699dnvdPatchThird Party AdvisoryWEB
- github.com/DIYgod/RSSHub/security/advisories/GHSA-pgjj-866w-fc5cnvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-pgjj-866w-fc5cghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2021-21278ghsaADVISORY
- www.npmjs.com/package/rsshubnvdProductThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.