← Back

Node Extend Project

node-extend_project

1 CVE • 1 product

Products (1)

Click to collapse
Toggle
Node Extend
node-extend

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Node Extend Project
1Node Extend
Nov 21, 2024
Jun 10, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` located within `lib/extend.js` is executed by the `eval` function, resul...Show more
node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` located within `lib/extend.js` is executed by the `eval` function, resulting in code execution.Show less