node-import `params` argument can be controlled by users without any sanitization
- Severity:
- High
Description
This affects all versions of package node-import. The params argument of module function can be controlled by users without any sanitization. This is then provided to the “eval” function located in line 79 in the index file index.js.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 0.9.2
References
Related Issues
- Prototype pollution in controlled-merge - CVE-2020-28268
- Electerm users can run dangrous code through link or command line - CVE-2026-43944
- Improper Validation and Sanitization in url-parse - CVE-2020-8124
- Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry - CVE-2026-59891
You might also like:
- Tags:
- npm
- node-import
Anything's wrong? Let us know Last updated on January 27, 2023


