CWE-95— Improper Neutralization of Directives in Dynamically Evaluated Code (Eval Injection)
The product receives input from an upstream component, but it does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call (e.g. "eval").— MITRE CWE catalog
210 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-95page 5 of 5
- CVE-2026-24474MEDIUMCVSS 5.3EG 5.32026-01-24
Dioxus Components is a shadcn-style component library for the Dioxus app framework. Prior to commit 41e4242ecb1062d04ae42a5215363c1d9fd4e23a, `use_animated_open` formats a string for `eval` with an `id` that can be user supplied. Commit 41…
- CVE-2024-32649MEDIUMCVSS 5.3EG 5.32024-04-25
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `sqrt` builtin can result in double eval vulnerability when the argument has side-effects. It can be seen that the `build…
- CVE-2024-32647MEDIUMCVSS 5.3EG 5.32024-04-25
Vyper is a pythonic Smart Contract Language for the Ethereum virtual machine. In versions 0.3.10 and prior, using the `create_from_blueprint` builtin can result in a double eval vulnerability when `raw_args=True` and the `args` argument ha…
- CVE-2026-105315MEDIUMCVSS 4.7EG 4.72026-10-05
A vulnerability has been found in django-haystack up to 3.3.0. Affected is the function _to_python of the file haystack/backends/elasticsearch_backend.py of the component more_like_this Template Tag Handler. Such manipulation of the argume…
- CVE-2026-6652MEDIUMCVSS 4.7EG 4.72026-04-20
A weakness has been identified in Pagekit CMS up to 1.0.18. This issue affects the function evaluate of the file app/modules/view/src/PhpEngine.php of the component StringStorage Template Handler. This manipulation causes improper neutrali…
- CVE-2025-49598MEDIUMCVSS 4.4EG 4.42025-06-13
conda-forge-ci-setup is a package installed by conda-forge each time a build is run on CI. The conda-forge-ci-setup-feedstock setup script is vulnerable due to the unsafe use of the eval function when parsing version information from a cus…
- CVE-2020-5217MEDIUMCVSS 4.4EG 4.42020-01-23
In Secure Headers (RubyGem secure_headers), a directive injection vulnerability is present in versions before 3.8.0, 5.1.0, and 6.2.0. If user-supplied input was passed into append/override_content_security_policy_directives, a semicolon c…
- CVE-2026-101861MEDIUMCVSS 4.1EG 4.12026-09-28
Langflow 1.0.16 before 1.12.0 and 0.0.94 before 1.12.0 contain an unsafe eval() vulnerability in schema.py that allows authenticated attackers to achieve code execution by placing a Python object with a malicious __repr__ method into compo…
- CVE-2026-69662LOWCVSS 3.7EG 3.72026-09-29
The application uses unsafe functions that allow execution of inline scripts and string evaluation functions.
- CVE-2025-32435LOWCVSS 2.6EG 2.62025-04-15
Hydra is a Continuous Integration service for Nix based projects. Evaluation of untrusted non-flake nix code could potentially access secrets that are accessible by the hydra user/group. This should not affect the signing keys, that are ow…
Map vulnerabilities like CWE-95 to your infrastructure
EchelonGraph correlates every CVE — across CWE-95 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →