CVE-2017-16088
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 3.5%
exploitation probability
3.5%top 12% of all CVEs
observed exploitation
nono source reports it
The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.
Affected products
HackerOne · safe-eval node module