Description
Under certain circumstances, unevaling untrusted data can produce output code that will create objects with polluted prototypes when later evaled, meaning the output data can be a different shape from the input data.
Recommendation
Update the devalue package to the latest compatible version. Followings are version details:
- Affected version(s): <= 5.6.2
- Patched version(s): 5.6.3
References
Could your website be exposed too?
SmartScanner can check your website for devalue `uneval`ed code can create objects with polluted prototypes when `eval`ed and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Axios: Nested axios option objects can consume polluted prototype values - Vulnerability
- Vega vulnerable to arbitrary code execution when clicking href links - Vulnerability
- @saltcorn/plugins-loader unsanitized plugin name leads to a remote code execution (RCE) vulnerability when creating plug - Vulnerability
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-876r-hj45-fw7g - Vulnerability


