Launch Week Day 1: Announcing Security Design Review
UNKNOWN npm

devalue `uneval`ed code can create objects with polluted prototypes when `eval`ed

GHSA-8qm3-746x-r74r

Published ยท Modified

Description

Under certain circumstances, unevaling untrusted data can produce output code that will create objects with polluted prototypes when later evaled, meaning the output data can be a different shape from the input data.

Ready to move

Start Securing

Free, no credit card | First findings in minutes