{"id":"GHSA-qxc2-j82w-r537","summary":"Faker: helpers.fake exploitable into arbritary code execution","details":"### Summary\n\n`faker.helpers.fake` can be tricked into arbritary code execution.\n\n### Details\n\nfakeEval.resolveProperty resolves properties on functions itself instead of resolving the nested function first.\nThis can be addressed by recursively calling resolveProperty instead of accessing the property after one iteration.\n\n### PoC\n\nGo to https://fakerjs.dev/\nOpen Browser console and run\n\n````ts\nawait enableFaker(); // or import faker\nfaker.rawDefinitions.test = (() =\u003e () =\u003e {}); // Any function that returns a function\nfaker.helpers.fake(`{{test.constructor(alert('PowerLevel: Eval'))}}`);\n````\n\n### Impact\n\nThe Fake method claims:\n\n\u003e It is also NOT possible to use any non-faker methods or plain javascript in such patterns.\n\nWhich is objectively false, since any global gets fully accessible in the fake string.","aliases":["CVE-2026-73231"],"modified":"2026-09-02T14:30:05.884430461Z","published":"2026-09-02T14:20:14Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-09-02T14:20:14Z","nvd_published_at":"2026-08-11T20:18:48Z","cwe_ids":["CWE-95"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/faker-js/faker/security/advisories/GHSA-qxc2-j82w-r537"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73231"},{"type":"WEB","url":"https://github.com/faker-js/faker/pull/3852"},{"type":"WEB","url":"https://github.com/faker-js/faker/commit/54586208f904012f57c50b46cc1ad32bcbe4bfb7"},{"type":"PACKAGE","url":"https://github.com/faker-js/faker"},{"type":"WEB","url":"https://github.com/faker-js/faker/releases/tag/v10.5.0"}],"affected":[{"package":{"name":"@faker-js/faker","ecosystem":"npm","purl":"pkg:npm/%40faker-js/faker"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"10.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-qxc2-j82w-r537/GHSA-qxc2-j82w-r537.json","last_known_affected_version_range":"\u003c= 10.4.0"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}