{"id":"GHSA-4wv4-mgfq-598v","summary":"Code injection in nobelprizeparser","details":"Code injection through use of eval.","modified":"2021-03-12T19:13:27Z","published":"2021-03-12T23:00:19Z","database_specific":{"github_reviewed_at":"2021-03-12T19:13:27Z","nvd_published_at":null,"cwe_ids":["CWE-94"],"severity":"CRITICAL","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/AnneTheDev/nobelprize/security/advisories/GHSA-4wv4-mgfq-598v"},{"type":"WEB","url":"https://github.com/AnneTheDev/nobelprize/commit/00639d375b0efd097bc1eca18d9dc021691b9286"},{"type":"WEB","url":"https://www.npmjs.com/package/nobelprizeparser"}],"affected":[{"package":{"name":"nobelprizeparser","ecosystem":"npm","purl":"pkg:npm/nobelprizeparser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/03/GHSA-4wv4-mgfq-598v/GHSA-4wv4-mgfq-598v.json"}}],"schema_version":"1.9.0"}