Vulnerability Details CVE-2017-16088
The safe-eval module describes itself as a safer version of eval. By accessing the object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.03
EPSS Ranking 85.7%
CVSS Severity
CVSS v3 Score 10.0
CVSS v2 Score 10.0
Products affected by CVE-2017-16088
-
cpe:2.3:a:safe-eval_project:safe-eval:0.0.0
-
cpe:2.3:a:safe-eval_project:safe-eval:0.1.0
-
cpe:2.3:a:safe-eval_project:safe-eval:0.2.0
-
cpe:2.3:a:safe-eval_project:safe-eval:0.3.0