The Safer Eval Project maintains a focused, specialized library designed to provide safer evaluation capabilities in Python environments, serving a narrow but structurally important role in codebases that require controlled code execution. The sparse vulnerability signal reflects this library's limited scope and specialized deployment context. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Safer Eval Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10760CRITICAL safer-eval before 1.3.2 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code. | Oct 15, 2019 | 9.9 | 32 | NO | NO |
CVE-2019-10769CRITICAL safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are vulnerable to Arbitrary Code Execution via gen | Dec 6, 2019 | 9.8 | 31 | NO | NO |
CVE-2019-10759CRITICAL safer-eval before 1.3.4 are vulnerable to Arbitrary Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code. | Oct 15, 2019 | 9.9 | 31 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Safer Eval Project.
Media articles that mention a CVE ID that affects a product developed by Safer Eval Project — matched by CVE ID, not by vendor name.