CVE-2019-10760

CRITICAL

safer-eval < 1.3.2 - Arbitrary Code Execution via Constructor Properties

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-10760. PoCs published by lirantal.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2019-10760, targeting a prototype pollution vulnerability in the `safer-eval` npm package (version 1.3.1 and below). The exploit leverages JavaScript's prototype chain to bypass sandboxing and achieve remote code execution (RCE) via `child_process.execSync`.

Description

safer-eval before 1.3.2 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.

Exploits (1)

nomisec WORKING POC
by lirantal · poc
https://github.com/lirantal/safer-eval-cve-CVE-2019-10760

This repository contains a functional exploit for CVE-2019-10760, targeting a prototype pollution vulnerability in the `safer-eval` npm package (version 1.3.1 and below). The exploit leverages JavaScript's prototype chain to bypass sandboxing and achieve remote code execution (RCE) via `child_process.execSync`.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: safer-eval npm package <= 1.3.1
No auth needed
Prerequisites: Node.js environment with vulnerable `safer-eval` installed
MITRE ATT&CK
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (1)

Core 1
Core References
Patch, Third Party Advisory x_refsource_confirm
https://snyk.io/vuln/SNYK-JS-SAFEREVAL-473029

Scores

CVSS v3 9.9
EPSS 0.1085
EPSS Percentile 93.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Details

Status published
Products (2)
npm/safer-eval 0 - 1.3.2npm
safer-eval_project/safer-eval < 1.3.2
Published Oct 15, 2019
Tracked Since Feb 18, 2026