QID 980452
QID 980452: Nodejs (npm) Security Update for rsshub (GHSA-pgjj-866w-fc5c)
Security update has been released for rsshub to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Some routes use `eval` or `Function constructor`, which may be injected by the target site with unsafe code, causing server-side security issues
Solution
Temporarily removed the problematic route and added a `no-new-func` rule to eslint
Self-built users should upgrade to 7f1c430 and later as soon as possible
Self-built users should upgrade to 7f1c430 and later as soon as possible
Vendor References
- GHSA-pgjj-866w-fc5c -
github.com/advisories/GHSA-pgjj-866w-fc5c
CVEs related to QID 980452
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pgjj-866w-fc5c | rsshub |
|