CVE-2017-16226
CVE-2017-16226
The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.
Affected products
HackerOne · static-eval node module node moduleWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →