Skip to content

Conversation

@aikido-autofix
Copy link
Contributor

Patch critical RCE vulnerability in cjs-module-lexer by sanitizing input deserialization to prevent arbitrary code execution risks

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-10017
MEDIUM
Arbitrary Code Execution vulnerability in deserialization process using unsanitized eval() on user input, allowing attackers to inject and execute malicious JavaScript, potentially compromising the system.
🔗 Related Tasks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant