CVE-2019-15657: Eslint-Utils Project Eslint-Utils
Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.
In eslint-utils before 1.4.1, the getStaticValue function can execute arbitrary code.
Affected products
- Eslint-Utils Project Eslint-Utils: before 1.4.1 (fixed in 1.4.1)
Published 2019-08-26. Last modified 2026-06-17.