substack/node-syntax-error

substack/node-syntax-error

Releases14
Frequency5 months 3 days
Last Release

CVE History

CVEPublishedCVSS v3CVSS v2
10 HIGH

Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.