-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability stems from prototype pollution via JavaScript's built-in functions that safe-eval fails to properly sanitize. Each listed function: 1) Is explicitly demonstrated in GitHub issues as exploitation vectors 2) Provides access to constructor chains through exception handling 3) Enables access to Node.js process object through prototype pollution 4) Directly correlates with CVE description of vulnerable functions. The high confidence comes from multiple reproducible PoCs showing RCE through these specific function usages.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| safe-eval | npm | <= 0.4.2 |
KEV Misses 88% of Exploited CVEs- Get the report