CVE-2017-16226: Static-Eval Project Static-Eval

Critical severity, CVSS 9.8. EPSS: 3.6% chance of exploitation in the next 30 days.

The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.

Affected products

Published 2018-06-07. Last modified 2026-06-17.