Description
Some routes use eval or Function constructor, which may be injected by the target site with unsafe code, causing server-side security issues
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.0.0
References
Related Issues
- Code injection in plupload - CVE-2021-23562
- Command injection in launchpad - CVE-2021-23330
- Command Injection in lodash - lodash-es - CVE-2021-23337
- Widget feature vulnerability allowing to execute JavaScript code using undo functionality - CVE-2021-32808
You might also like:
- Tags:
- npm
- rsshub
Anything's wrong? Let us know Last updated on February 01, 2023


