Description
Some routes use eval or Function constructor, which may be injected by the target site with unsafe code, causing server-side security issues
Recommendation
No fix is available yet. Followings are affected versions:
- <= 1.0.0
References
Related Issues
- Angular Expressions - Remote Code Execution - CVE-2021-21277
- Command Injection Vulnerability in systeminformation - CVE-2021-21388
- Command Injection in @theia/messages - CVE-2021-28162
- Code Injection in cd-messenger - CVE-2020-7675
- Tags:
- npm
- rsshub
Anything's wrong? Let us know Last updated on February 01, 2023