Assuming there is no browser-side security loophole that can be used to modify someone's computer, I don't understand how using eval
could lead to any real threat.
Could someone explain how that could be possible. Someone could display something on a user's computer, but no real harm could be done without a redirection or accepted download. No server-side damage could be done, right?