High severity7.5NVD Advisory· Published Apr 11, 2023· Updated Jun 17, 2026
CVE-2023-26121
CVE-2023-26121
Description
All versions of the package safe-eval are vulnerable to Prototype Pollution via the safeEval function, due to improper sanitization of its parameter content.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
safe-evalnpm | <= 0.4.2 | — |
Affected products
3- cpe:2.3:a:safe-eval_project:safe-eval:*:*:*:*:*:node.js:*:*Range: <=0.4.1
- safe-eval/safe-evaldescription
Patches
Vulnerability mechanics
References
5- gist.github.com/seongil-wi/9d9fc0cc5b7b130419cd45827e59c4f9nvdExploitThird Party AdvisoryWEB
- github.com/hacksparrow/safe-eval/issues/28nvdExploitIssue TrackingThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-SAFEEVAL-3373062nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-hcg3-56jf-x4vhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-26121ghsaADVISORY
News mentions
0No linked articles in our index yet.