Executive brief
eye.js is a JavaScript testing library used to detect security vulnerabilities. Version 1.2.0 contains a defect where all tests pass unconditionally, causing security checks to fail silently—potentially allowing vulnerable code to ship to production without detection. This could undermine the security assurance that developers rely on when using the tool.
Technical details
The vulnerability is a logic defect in the test framework itself: in version 1.2.0, all tests are forced to succeed regardless of actual test results. This is a test harness bug rather than a code execution vulnerability. The defect affects only users who deploy eye.js specifically to scan for security vulnerabilities; users running the library for other purposes are unaffected. The vulnerability has been patched in version 1.2.1, and the fix is available via a simple upgrade.
Affected products
- arguiot eye.js 1.2.0
Timeline
- 2019-10-05: disclosed
- 2019-10-05: patched: patch released as v1.2.1