VDB
Sign up
MEDIUM6.5

GHSA-8g4m-cjm2-96wq

Sandbox escape in notevil and argencoders-notevil

Details

This affects all versions of package notevil; all versions of package argencoders-notevil. It is vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing an attacker to add or modify an object's prototype. **Note:** This vulnerability derives from an incomplete fix in [SNYK-JS-NOTEVIL-608878](https://security.snyk.io/vuln/SNYK-JS-NOTEVIL-608878). This package has been deprecated.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/notevil
Introduced in: 0

No fixed version published yet for notevil (npm). Pin to a known-safe version or switch to an alternative.

npm/argencoders-notevil
Introduced in: 0

No fixed version published yet for argencoders-notevil (npm). Pin to a known-safe version or switch to an alternative.

References