easyPhone Screen

What are the main security risks of using the 'eval()' function in Node.js?

810 views
01

Understand the problem

Tests security awareness regarding dynamic code execution.

securitybest-practiceseval
02

Attempt it yourself

Sketch your approach before reading the solution — that's what interviews test.

Stuck? AI Nudge Available

Get a conceptual hint to guide your logic without spoiling the final implementation.

03

Study the solution

The solution is waiting

Give it an honest attempt first — then compare your thinking with the full walkthrough.

04

Read the code

Replace eval with safe parsing / dispatch
// ❌ never: executes whatever the client sent
// const data = eval('(' + req.body + ')');

// ✅ parse data, don't execute it
const data = JSON.parse(req.body);

// ✅ choose behavior via a map, not generated code
const ops = { add: (a, b) => a + b, sub: (a, b) => a - b };
const fn = ops[req.query.op] ?? (() => { throw new Error('bad op'); });
05

Join the discussion

Discussion (0)

Sign in to join the discussion.

No responses yet. Be the first to share what you think.