VYPR

npm package

accesslog

pkg:npm/accesslog

Vulnerabilities (1)

  • CVE-2022-25760HigMar 17, 2022
    affected <= 0.0.2

    All versions of package accesslog are vulnerable to Arbitrary Code Injection due to the usage of the Function constructor without input sanitization. If (attacker-controlled) user input is given to the format option of the package's exported constructor function, it is possible f