Eval Vm Compilefunction Injection

Untrusted user input in `vm.compileFunction()` can result in code injection.

IndexedPublic repositoryHighMedium confidenceVerifiedLGPL-3.0-onlyjavascript
greprules fetch gitlab-sast-rules-lgpl-javascript-eval-rule-vm-compilefunction-injection --engine opengrep

Description

Untrusted user input in `vm.compileFunction()` can result in code injection.

Detection target

Not provided

Recommended fix

Not provided

False-positive notes

Not provided

Community feedback

Sign in to report false positives, mark this rule useful, or suggest metadata improvements.