VDB
Sign up
HIGH

GHSA-7r5f-7qr4-pf6q

Sandbox Breakout / Arbitrary Code Execution in notevil

Quick fix

GHSA-7r5f-7qr4-pf6q — notevil: upgrade to the fixed version with the command below.

npm install notevil@1.3.2

Details

Versions of `notevil` prior to 1.3.2 are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to prevent access to the `Function` constructor by not checking the return values of function calls. This allows attackers to access the Function prototype's constructor leading to the Sandbox Escape. An example payload is: ``` var safeEval = require('notevil') var input = "" + "function fn() {};" + "var constructorProperty = Object.getOwnPropertyDescriptors(fn.__proto__).constructor;" + "var properties = Object.values(constructorProperty);" + "properties.pop();" + "properties.pop();" + "properties.pop();" + "var Function = properties.pop();" + "(Function('return this'))()"; safeEval(input)```

## Recommendation

Upgrade to version 1.3.2 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/notevil
Introduced in: 0Fixed in: 1.3.2
Fixnpm install notevil@1.3.2

References