{"id":"CVE-2021-26276","aliases":["GHSA-w8h4-vw8f-rvvj"],"url":"https://o3.security/vulnerability/CVE-2021-26276","summary":"Improper Control of Dynamically-Managed Code Resources in config-shield","details":"scripts/cli.js in the GoDaddy node-config-shield (aka Config Shield) package before 0.2.2 for Node.js calls eval when processing a set command. NOTE: the vendor reportedly states that this is not a vulnerability. The set command was not intended for use with untrusted data","published":"2021-01-27T20:15:13.863Z","modified":"2026-07-08T05:57:08.570384635Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"config-shield","fixedVersion":"0.2.3"}],"fix":{"url":"https://github.com/godaddy/node-config-shield/commit/cdba5d3a7accd661ffbc52e208153464bd0d9da6","label":"godaddy/node-config-shield@cdba5d3"},"references":[{"type":"FIX","url":"https://github.com/godaddy/node-config-shield/commit/cdba5d3a7accd661ffbc52e208153464bd0d9da6"},{"type":"EVIDENCE","url":"https://advisory.checkmarx.net/advisory/CX-2021-4773"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:57:08.570384635Z"}}