CRITICAL9.8
GHSA-6jg8-7333-554w
Sandbox Breakout in realms-shim
Quick fix
GHSA-6jg8-7333-554w — realms-shim: upgrade to the fixed version with the command below.
npm install realms-shim@1.2.0Details
Versions of `realms-shim` prior to 1.2.0 are vulnerable to a Sandbox Breakout. `Reflect.construct` can be used on the sandboxed Function constructor to reach the prototypes of the primal Realm, which may allow an attacker to escape the sandbox and execute arbitrary code.
## Recommendation
Upgrade to version 1.2.0 or later.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/Agoric/realms-shim/security/advisories/GHSA-6jg8-7333-554w[WEB]
- https://github.com/Agoric/realms-shim[WEB]
- https://github.com/advisories/GHSA-6jg8-7333-554w[ADVISORY]
- https://snyk.io/vuln/SNYK-JS-REALMSSHIM-471680[WEB]
- https://www.npmjs.com/advisories/1180[WEB]
- https://www.npmjs.com/advisories/1181[WEB]
- https://www.npmjs.com/advisories/1182[WEB]
- https://www.npmjs.com/advisories/1190[WEB]
- https://www.npmjs.com/advisories/1191[WEB]