Vulnerabilities/

Improper Input Validation in access-policy

Severity:
High

Description

access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the template function is executed by the eval function resulting in code execution.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
access-policy
Anything's wrong? Let us know Last updated on February 01, 2023