VDB
Sign up
CRITICAL9.9

GHSA-hgch-jjmr-gp7w

Sandbox Breakout / Arbitrary Code Execution in safer-eval

Quick fix

GHSA-hgch-jjmr-gp7w — safer-eval: upgrade to the fixed version with the command below.

npm install safer-eval@1.3.2

Details

Versions of `safer-eval` before 1.3.2 are vulnerable to Sandbox Escape leading to Remote Code Execution. A payload using constructor properties can escape the sandbox and execute arbitrary code.

## Recommendation

Upgrade to version 1.3.2.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/safer-eval
Introduced in: 0Fixed in: 1.3.2
Fixnpm install safer-eval@1.3.2

References