cjs-module-lexer is vulnerable to Improper Control of Generation of Code ('Code Injection')
55
Medium Risk
Affected versions of this package are vulnerable to Arbitrary Code Execution via Insecure Input Deserialization due to the decode function using the eval() function on potential user-supplied input (str) without proper sanitization or validation. An attacker can exploit this by injecting malicious JavaScript code as the str argument, which will be directly evaluated and executed within the application's context, potentially leading to system compromise, data theft, or other malicious activities.
You are affected if you are using a version that falls within the vulnerable range.
cjs-module-lexer is vulnerable to Improper Control of Generation of Code ('Code Injection') in versions 0.4.3 - 2.1.0.
Upgrade the cjs-module-lexer library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant