Code Injection
This CVE has been marked as a False Positive and has been removed.
This CVE has been marked as a False Positive and has been removed.
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in static-eval.
Untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.
In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.