{"id":"GHSA-8whr-v3gm-w8h9","summary":"Duplicate Advisory: Command Injection in node-rules","details":"## Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-f78f-353m-cf4j. This link is maintained to preserve external references.\n\n## Original Description\nVersions of `node-rules` prior to 5.0.0 are vulnerable to Command Injection. The package fails to sanitize input rules and passes it directly to an `eval` call when using the `fromJSON` function. This may allow attackers to execute arbitrary code in the system if the rules are user-controlled.\n\n\n## Recommendation\n\nUpgrade to version 5.0.0 or later.","modified":"2026-02-03T03:08:01.789631Z","published":"2020-09-03T15:51:04Z","withdrawn":"2026-01-23T22:49:42Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-08-31T19:01:30Z","nvd_published_at":null,"cwe_ids":["CWE-78"]},"references":[{"type":"WEB","url":"https://github.com/mithunsatheesh/node-rules/issues/84"},{"type":"WEB","url":"https://github.com/mithunsatheesh/node-rules/commit/100862223904bb6478fcc33b701c7dee11f7b832"},{"type":"PACKAGE","url":"https://github.com/mithunsatheesh/node-rules"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-NODERULES-560426"}],"affected":[{"package":{"name":"node-rules","ecosystem":"npm","purl":"pkg:npm/node-rules"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.0.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-8whr-v3gm-w8h9/GHSA-8whr-v3gm-w8h9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L"}]}