cve/2021/CVE-2021-21278.md
2025-09-29 21:09:30 +02:00

1.0 KiB

CVE-2021-21278

Description

RSSHub is an open source, easy to use, and extensible RSS feed generator. In RSSHub before version 7f1c430 (non-semantic versioning) there is a risk of code injection. Some routes use eval or Function constructor, which may be injected by the target site with unsafe code, causing server-side security issues The fix in version 7f1c430 is to temporarily remove the problematic route and added a no-new-func rule to eslint.

POC

Reference

Github

No PoCs found on GitHub currently.