GHSA-3gx7-xhv7-5mx3

Suggest an improvement
Source
https://github.com/advisories/GHSA-3gx7-xhv7-5mx3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/08/GHSA-3gx7-xhv7-5mx3/GHSA-3gx7-xhv7-5mx3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3gx7-xhv7-5mx3
Aliases
Published
2019-08-26T16:59:56Z
Modified
2026-09-10T03:48:25Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Arbitrary Code Execution in eslint-utils
Details

Versions of eslint-utils >=1.2.0 or <1.4.1 are vulnerable to Arbitrary Code Execution. The getStaticValue does not properly sanitize user input allowing attackers to supply malicious input that executes arbitrary code during the linting process. The getStringIfConstant and getPropertyName functions are not affected.

Recommendation

Upgrade to version 1.4.1 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-20"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-06-16T20:55:11Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

npm / eslint-utils

Package

Affected ranges

Type
SEMVER
Events
Introduced
1.2.0
Fixed
1.4.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/08/GHSA-3gx7-xhv7-5mx3/GHSA-3gx7-xhv7-5mx3.json"