High severity8.8NVD Advisory· Published Apr 11, 2023· Updated Jun 17, 2026
CVE-2023-26122
CVE-2023-26122
Description
All versions of the package safe-eval are vulnerable to Sandbox Bypass due to improper input sanitization. The vulnerability is derived from prototype pollution exploitation. Exploiting this vulnerability might result in remote code execution ("RCE"). Vulnerable functions: __defineGetter__, stack(), toLocaleString(), propertyIsEnumerable.call(), valueOf().
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
safe-evalnpm | <= 0.4.2 | — |
Affected products
3- cpe:2.3:a:safe-eval_project:safe-eval:*:*:*:*:*:node.js:*:*Range: <=0.4.1
- safe-eval/safe-evaldescription
Patches
Vulnerability mechanics
References
10- gist.github.com/seongil-wi/2db6cb884e10137a93132b7f74879ccenvdExploitThird Party AdvisoryWEB
- github.com/hacksparrow/safe-eval/issues/27nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/hacksparrow/safe-eval/issues/31nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/hacksparrow/safe-eval/issues/32nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/hacksparrow/safe-eval/issues/33nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/hacksparrow/safe-eval/issues/34nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/hacksparrow/safe-eval/issues/35nvdExploitIssue TrackingThird Party AdvisoryWEB
- security.snyk.io/vuln/SNYK-JS-SAFEEVAL-3373064nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-79xf-67r4-q2jjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-26122ghsaADVISORY
News mentions
0No linked articles in our index yet.