justmoon/node-extend
Releases14
Frequency5 months 3 weeks
Last Release
Stars343
Simple function to extend objects
CVE History
| CVE | Affected | Published | CVSS v3 | CVSS v2 |
|---|---|---|---|---|
| <= 0.2.0 | 9.8 CRITICAL | 7.5 HIGH | ||
node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` located within `lib/extend.js` is executed by the `eval` function, resulting in code execution. | ||||