MEDIUM
GHSA-5mjw-6jrh-hvfq
Sandbox Breakout / Arbitrary Code Execution in static-eval
Quick fix
GHSA-5mjw-6jrh-hvfq — static-eval: upgrade to the fixed version with the command below.
npm install static-eval@2.0.0Details
Affected versions of `static-eval` pass untrusted user input directly to the global function constructor, resulting in an arbitrary code execution vulnerability when user input is parsed via the package.
## Proof of concept ```js var evaluate = require('static-eval'); var parse = require('esprima').parse; var src = '(function(){console.log(process.pid)})()'; var ast = parse(src).body[0].expression; var res = evaluate(ast, {}); // Will print the process id ```
## Recommendation
Update to version 2.0.0 or later.
Are you affected?
Enter the version of the package you're using.