CRITICAL9.9
GHSA-hgch-jjmr-gp7w
Sandbox Breakout / Arbitrary Code Execution in safer-eval
Quick fix
GHSA-hgch-jjmr-gp7w — safer-eval: upgrade to the fixed version with the command below.
npm install safer-eval@1.3.2Details
Versions of `safer-eval` before 1.3.2 are vulnerable to Sandbox Escape leading to Remote Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.
## Recommendation
Upgrade to version 1.3.2.
Are you affected?
Enter the version of the package you're using.