All versions of package safe-eval are vulnerable to Prototype Pollution which allows an attacker to add or modify properties of the Object.prototype.Consolidate when using the function safeEval. This is because the function uses vm variable, leading an attacker to modify properties of the Object.prototype.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Apr 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: snyk
Published: 2022-12-21T01:21:43.830Z
Updated: 2025-04-16T14:42:09.443Z
Reserved: 2022-02-24T00:00:00.000Z
Link: CVE-2022-25904

Updated: 2024-08-03T04:49:44.295Z

Status : Modified
Published: 2022-12-20T05:15:11.487
Modified: 2025-04-16T15:15:50.550
Link: CVE-2022-25904

No data.