MEDIUM
GHSA-9gxr-rhx6-4jgv
Sandbox Breakout / Prototype Pollution in notevil
Quick fix
GHSA-9gxr-rhx6-4jgv — notevil: upgrade to the fixed version with the command below.
npm install notevil@1.3.3Details
Versions of `notevil` prior to 1.3.3 are vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing attacker to add or modify an object's prototype.
Evaluating the payload ```try{a[b];}catch(e){e.constructor.constructor('return __proto__.arguments.callee.__proto__.polluted=true')()}``` add the `polluted` property to Function.
## Recommendation
Upgrade to version 1.3.3 or later.
Are you affected?
Enter the version of the package you're using.