CVE-2017-16226: Static-Eval Project Static-Eval
Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.
The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.
Affected products
- Static-Eval Project Static-Eval: before 2.0.0 (fixed in 2.0.0)
Published 2018-06-07. Last modified 2026-06-17.