VDB

GCVE-110-NPM-2026-033167

GCVE-110-NPM-2026-033167
Advisory Published
Vulnetix · Advisory published July 15, 2026
[P-EVAL-VAR] Dynamic code execution via eval — matched: prepublishOnly: node --eval "console.error('ERROR: Trying to publish a package that has been compiled in full compilation mode. This is not allowed.\nPlease delete and rebuild the package with partial compilation mode, before attempting to publish.\n')" && exit 1

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Affected Products

VendorProductVersionsPlatforms
npm@magic-xpa/angular* (affected)

References

advisory

Browse GCVE Records

67,584 records in the GCVE database · Updated August 12, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›