This affects all versions of package safe-eval. It is possible for an malicious user to run an arbitrary command on the host machine.
safe-eval project safe-eval