@rudderstack/rudder-sdk-node is vulnerable to Deserialization of Untrusted Data leading to Remote Code Execution
88
High Risk
Affected versions of this package are vulnerable to Remote Code Execution via Insecure Deserialization, where an attacker with write access to the Redis persistence queue could inject malicious JavaScript code into a job's eventData; this code would then be executed on the server during deserialization using the unsafe eval() function when the job was processed, allowing for system compromise, which was fixed in v3.0.0 by replacing eval() with safe JSON.parse().
You are affected if you are using a version that falls within the vulnerable range.
@rudderstack/rudder-sdk-node is vulnerable to Deserialization of Untrusted Data leading to Remote Code Execution in versions 2.0.0 - 2.1.11.
Upgrade the @rudderstack/rudder-sdk-node library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant