VDB
Sign up
CRITICAL

GHSA-mmqv-m45h-q2hp

Sandbox Breakout / Arbitrary Code Execution in localeval

Quick fix

GHSA-mmqv-m45h-q2hp — localeval: upgrade to the fixed version with the command below.

npm install localeval@15.3.0

Details

All versions of `localeval` are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context through `constructor.constructor`. This may allow attackers to execute arbitrary code in the system. Evaluating the payload ``` constructor.constructor("return process.env")() ```

returns the contents of `process.env`.

## Recommendation

No fix is currently available. Consider using an alternative package until a fix is made available.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/localeval
Introduced in: 0Fixed in: 15.3.0
Fixnpm install localeval@15.3.0

References