{"id":"GHSA-29xr-v42j-r956","summary":"thenify before 3.3.1 made use of unsafe calls to `eval`.","details":"Versions of thenify prior to 3.3.1 made use of unsafe calls to `eval`. Untrusted user input could thus lead to arbitrary code execution on the host. The patch in version 3.3.1 removes calls to `eval`.","aliases":["CVE-2020-7677"],"modified":"2026-05-05T16:40:11.986544Z","published":"2022-07-18T19:15:29Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-07-18T19:15:29Z","nvd_published_at":"2022-07-25T14:15:00Z","cwe_ids":["CWE-78"],"severity":"CRITICAL"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7677"},{"type":"WEB","url":"https://github.com/thenables/thenify/issues/29"},{"type":"WEB","url":"https://github.com/thenables/thenify/commit/0d94a24eb933bc835d568f3009f4d269c4c4c17a"},{"type":"PACKAGE","url":"https://github.com/thenables/thenify"},{"type":"WEB","url":"https://github.com/thenables/thenify/blob/master/index.js%23L17"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2022/09/msg00039.html"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/MTEUUTNIEBHGKUKKLNUZSV7IEP6IP3Q3"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UM6XJ73Q3NAM5KSGCOKJ2ZIA6GUWUJLK"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-572317"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-THENIFY-571690"}],"affected":[{"package":{"name":"thenify","ecosystem":"npm","purl":"pkg:npm/thenify"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.3.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-29xr-v42j-r956/GHSA-29xr-v42j-r956.json"}},{"package":{"name":"org.webjars.npm:thenify","ecosystem":"Maven","purl":"pkg:maven/org.webjars.npm/thenify"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.1"}]}],"versions":["3.1.0","3.3.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/07/GHSA-29xr-v42j-r956/GHSA-29xr-v42j-r956.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}