CVE-2017-16226: Sandbox Breakout / Arbitrary Code Execution in static-eval

Severity: Critical

CVSS Score: 9.8

The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.