Vulnerabilities/

lilconfig Code Injection vulnerability

Severity:
High

Description

Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious input through the defaultLoaders function.

Recommendation

Update the lilconfig package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
lilconfig
Anything's wrong? Let us know Last updated on November 01, 2024