browser
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
SecuritySecurityscripts/eval.cjs
MEDIUMSecurityMEDIUM
scripts/eval.cjs
This module is a high-risk execution bridge: it takes attacker-/user-supplied JavaScript from the command line and performs `Runtime.evaluate` via Chrome DevTools Protocol inside a live page context, then prints returned values and exception text. While it contains no explicit persistence, network exfiltration to remote domains, or obfuscated payloads in this snippet, its primary function provides arbitrary code execution capability in the browser session if the CLI argument is attacker-influenced and/or if the local CDP endpoint is exposed/accessible. Treat as potentially dangerous and restrict invocation and CDP exposure.
Confidence: 82%Severity: 92%
Audit Metadata