CVE-2020-7710

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
21/08/2020
Last modified:
21/07/2021

Description

This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:safe-eval_project:safe-eval:*:*:*:*:*:node.js:*:*