Description
Some routes use eval or Function constructor, which may be injected by the target site with unsafe code, causing server-side security issues
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.0.0
References
Related Issues
- Code Injection in mosc - CVE-2020-7672
- Command Injection in @theia/messages - CVE-2021-28162
- GraphiQL introspection schema template injection attack - CVE-2021-41248
- Command Injection Vulnerability in systeminformation - CVE-2021-21388
You might also like:
- Tags:
- npm
- rsshub
Anything's wrong? Let us know Last updated on February 01, 2023


