Skip to content
Noroxi

eggjs records

2 published records for vendor eggjs.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
100%
Median publish → KEV
No record has entered KEV

All records

2 records
  • A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line

    CriticalCVSS 9.8Proof of conceptEPSS 12%

    eggjs · egg-scriptsAug 24, 2018

  • The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.

    CriticalCVSS 9.8No exploitEPSS 1%

    eggjs · extend2Jan 10, 2022