{"id":"CVE-2017-16226","details":"The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.","aliases":["GHSA-5mjw-6jrh-hvfq"],"modified":"2026-07-08T12:06:23.883213Z","published":"2018-06-07T02:29:07.800Z","references":[{"type":"ADVISORY","url":"https://maustin.net/articles/2017-10/static_eval"},{"type":"FIX","url":"https://github.com/substack/static-eval/pull/18"},{"type":"EVIDENCE","url":"https://nodesecurity.io/advisories/548"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/browserify/static-eval","events":[{"introduced":"0"},{"fixed":"5bba7905b0e797460b8f6c2e38ff6869146faab3"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.0.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:static-eval_project:static-eval:*:*:*:*:*:node.js:*:*"}}],"versions":["1.1.1","1.1.0","1.0.0","0.2.4","0.2.3","0.2.2","0.2.1","0.2.0","0.1.1","0.1.0","0.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-16226.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}