Description
Some routes use eval or Function constructor, which may be injected by the target site with unsafe code, causing server-side security issues
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.0.0
References
Related Issues
- Code Injection in cryo - CVE-2018-3784
- Code injection in electerm - CVE-2020-23256
- Angular Expressions - Remote Code Execution - CVE-2021-21277
- [thi.ng/egf] Potential arbitrary code execution of `#gpg`-tagged property values - CVE-2021-21412
- Tags:
- npm
- rsshub
Anything's wrong? Let us know Last updated on February 01, 2023