CVE-2026-27971: Js Require Dynamic Module And Symbol From Input

Calling Node's CommonJS `require()` with a non-literal module path and then dynamically indexing the loaded module by a non-literal symbol name is unsafe deserialization / dynamic code loading (CWE-502). If the path or symbol can come from request data (e.g. a deserialized payload or function parameters at an RPC boundary), an attacker can load any CommonJS

Provally CuratedPublic repositoryHighHigh confidenceVerifiedApache-2.0TS
greprules fetch cve-2026-27971-js-require-dynamic-module-and-symbol-from-input --engine opengrep

Description

Calling Node's CommonJS `require()` with a non-literal module path and then dynamically indexing the loaded module by a non-literal symbol name is unsafe deserialization / dynamic code loading (CWE-502). If the path or symbol can come from request data (e.g. a deserialized payload or function parameters at an RPC boundary), an attacker can load any CommonJS