VDB
Sign up
MEDIUM

GHSA-5mjw-6jrh-hvfq

Sandbox Breakout / Arbitrary Code Execution in static-eval

Quick fix

GHSA-5mjw-6jrh-hvfq — static-eval: upgrade to the fixed version with the command below.

npm install static-eval@2.0.0

Details

Affected versions of `static-eval` pass untrusted user input directly to the global function constructor, resulting in an arbitrary code execution vulnerability when user input is parsed via the package.

## Proof of concept ```js var evaluate = require('static-eval'); var parse = require('esprima').parse; var src = '(function(){console.log(process.pid)})()'; var ast = parse(src).body[0].expression; var res = evaluate(ast, {}); // Will print the process id ```

## Recommendation

Update to version 2.0.0 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/static-eval
Introduced in: 0Fixed in: 2.0.0
Fixnpm install static-eval@2.0.0

References