CWE-95Variant4 in KEV

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')

Incomplete in the CWE catalog · 174 CVEs mapped

174
CVEs mapped
4
In KEV
8.9
Median CVSS
What it is

The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").

Recent examples
8.1cvss
CVE-2026-79678

Freeipa: idm: freeipa: idp-add eval() reachable before authorization check allows environment disclosure and denial of service

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. This allows any authenticated IPA principal, regardless of privilege level, to enumerate and read the environment variables of the affected server process and to cause denial of service via memory exhaustion.

HIGHno explanation yet
epss
none
CVE-2026-85165

CVE-2026-85165 - UNKNOWN Severity Vulnerability

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until restart.

no explanation yet
0%
epss
8.8cvss
CVE-2026-65643

CVE-2026-65643 - HIGH Severity Vulnerability

Eval injection in cPanel 11.138.0.0 and earlier allows remote authenticated users to execute arbitrary code as root.

HIGHno explanation yet
1%
epss
The record
Technical detail
CWE ID
CWE-95
Abstraction
Variant
Structure
Simple
Status
Incomplete
References (2)