VDB
Sign up
CRITICAL9.8

GHSA-7cg8-pq9v-x98q

Sandbox Breakout in realms-shim

Quick fix

GHSA-7cg8-pq9v-x98q — realms-shim: upgrade to the fixed version with the command below.

npm install realms-shim@1.2.1

Details

Versions of `realms-shim` prior to 1.2.1 are vulnerable to a Sandbox Breakout. The Realms evaluation function has an option to apply Babel-like transformations to the source code before it reaches the evaluator. One portion of this transform pipeline exposed a primal-Realm object to the rewriting function. Confined code which used the evaluator itself could provide a malicious rewriter function that captured this object, and use it to breach the sandbox.

## Recommendation

Upgrade to version 1.2.1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/realms-shim
Introduced in: 0Fixed in: 1.2.1
Fixnpm install realms-shim@1.2.1

References