GHSA-7r5f-7qr4-pf6q
Sandbox Breakout / Arbitrary Code Execution in notevil
Quick fix
GHSA-7r5f-7qr4-pf6q — notevil: upgrade to the fixed version with the command below.
npm install notevil@1.3.2Details
Versions of `notevil` prior to 1.3.2 are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to prevent access to the `Function` constructor by not checking the return values of function calls. This allows attackers to access the Function prototype's constructor leading to the Sandbox Escape. An example payload is: ``` var safeEval = require('notevil') var input = "" + "function fn() {};" + "var constructorProperty = Object.getOwnPropertyDescriptors(fn.__proto__).constructor;" + "var properties = Object.values(constructorProperty);" + "properties.pop();" + "properties.pop();" + "properties.pop();" + "var Function = properties.pop();" + "(Function('return this'))()"; safeEval(input)```
## Recommendation
Upgrade to version 1.3.2 or later.
Are you affected?
Enter the version of the package you're using.