VYPR

Safe Eval Node Module

by Hackerone

CVEs (1)

  • CVE-2017-16088CriJun 7, 2018
    risk 0.00cvss 10.0epss 0.03

    The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.