Vulnerabilities > Eggjs

DATE CVE VULNERABILITY TITLE RISK
2022-01-10 CVE-2021-23568 Unspecified vulnerability in Eggjs Extend2 1.0.0
The package extend2 before 1.0.1 are vulnerable to Prototype Pollution via the extend function due to unsafe recursive merge.
network
low complexity
eggjs
critical
9.8
2018-08-24 CVE-2018-3786 OS Command Injection vulnerability in Eggjs Egg-Scripts
A command injection vulnerability in egg-scripts <v2.8.1 allows arbitrary shell command execution through a maliciously crafted command line argument.
network
low complexity
eggjs CWE-78
critical
9.8