CRITICAL9.6
GHSA-2jjq-x548-rhpv
isolated-vm has vulnerable CachedDataOptions in API
Quick fix
GHSA-2jjq-x548-rhpv — isolated-vm: upgrade to the fixed version with the command below.
npm install isolated-vm@4.3.7Details
### Impact If the untrusted v8 cached data is passed to the API through CachedDataOptions, the attackers can bypass the sandbox and run arbitrary code in the nodejs process. Version 4.3.7 changes the documentation to warn users that they should not accept `cachedData` payloads from a user.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/laverdet/isolated-vm/security/advisories/GHSA-2jjq-x548-rhpv[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2022-39266[ADVISORY]
- https://github.com/laverdet/isolated-vm/issues/379[WEB]
- https://github.com/laverdet/isolated-vm/commit/218e87a6d4e8cb818bea76d1ab30cd0be51920e8[WEB]
- https://github.com/laverdet/isolated-vm[PACKAGE]
- https://github.com/laverdet/isolated-vm/commits/v4.3.7[WEB]