hacksparrow / safe-eval

Safer version of eval()
257 stars 37 forks source link

Security vulnerability - CVE-2017-16088 #7

Closed donnd-t closed 6 years ago

donnd-t commented 6 years ago

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-16088

hacksparrow commented 6 years ago

Fixed in 0.4.0.

cpcallen commented 6 years ago

Unfortunately not fixed; see my comment on #5.