VDB
Sign up
MEDIUM

GHSA-9gxr-rhx6-4jgv

Sandbox Breakout / Prototype Pollution in notevil

Quick fix

GHSA-9gxr-rhx6-4jgv — notevil: upgrade to the fixed version with the command below.

npm install notevil@1.3.3

Details

Versions of `notevil` prior to 1.3.3 are vulnerable to Sandbox Escape leading to Prototype pollution. The package fails to restrict access to the main context, allowing attacker to add or modify an object's prototype.

Evaluating the payload ```try{a[b];}catch(e){e.constructor.constructor('return __proto__.arguments.callee.__proto__.polluted=true')()}``` add the `polluted` property to Function.

## Recommendation

Upgrade to version 1.3.3 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/notevil
Introduced in: 0Fixed in: 1.3.3
Fixnpm install notevil@1.3.3

References