PT-2026-70892 · Npm · Faker

CVE-2026-73231

·

Published

2026-08-11

·

Updated

2026-09-02

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Faker versions prior to 10.5.0
Description The faker.helpers.fake method in src/modules/helpers/eval.ts allows attacker-controlled fake templates to access the Function constructor through fakeEval.resolveProperty when a function returns another function. This flaw enables arbitrary JavaScript code execution.
Recommendations Update to version 10.5.0.

Exploit

Fix

Eval Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-73231
GHSA-QXC2-J82W-R537

Affected Products

Faker