Arbitrary Code Execution Vulnerability in Safer-Eval for JavaScript
CVE-2019-10759
9.9CRITICAL
What is CVE-2019-10759?
Safer-Eval, a JavaScript library used for safe evaluation of code, is susceptible to a vulnerability that allows for arbitrary code execution. Versions prior to 1.3.4 contain flaws where a crafted payload utilizing constructor properties can bypass the sandbox restrictions, leading to the potential execution of malicious code. This vulnerability underscores the importance of updating to the latest version to mitigate security risks associated with unsafe code execution.
Affected Version(s)
safer-eval All versions prior to version 1.3.4
