High severity7.8NVD Advisory· Published Aug 11, 2026· Updated Sep 9, 2026
CVE-2026-73231
CVE-2026-73231
Description
Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through fakeEval.resolveProperty when a function returns another function, enabling arbitrary JavaScript code execution. This issue is fixed in version 10.5.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@faker-js/fakernpm | < 10.5.0 | 10.5.0 |
Affected products
1Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-qxc2-j82w-r537ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-73231ghsaADVISORY
- github.com/faker-js/faker/commit/54586208f904012f57c50b46cc1ad32bcbe4bfb7nvdWEB
- github.com/faker-js/faker/pull/3852nvdWEB
- github.com/faker-js/faker/releases/tag/v10.5.0nvdWEB
- github.com/faker-js/faker/security/advisories/GHSA-qxc2-j82w-r537nvdWEB
News mentions
0No linked articles in our index yet.