VDB

GCVE-110-NPM-2026-033043

GCVE-110-NPM-2026-033043
Advisory Published
Vulnetix · Advisory published September 4, 2026
[P-EVAL-BASE64] Base64-decoded payload executed via eval — matched: import{request}from"@cqsjjb/jjb-common-lib/http.js";import dayjs from"dayjs";import{ID_NUMBER}from"../regular/index.js";function serialNumber(e,t){return(e.current-1)*e.pageSize+(t+1)}function toArrayString(value){return value?eval(value).map(String):[]}function interceptTheSuffix(e,t){return e.subs

Weaknesses (CWE)

CWE-506Embedded Malicious CodeCWE-200Exposure of Sensitive Information to an Unauthorized Actor

Affected Products

VendorProductVersionsPlatforms
npmzy-react-library1.3.23 (affected), 1.4.10 (affected)

References

advisory

Browse GCVE Records

540 records in the GCVE database · Updated September 8, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›