CRITICAL
GHSA-mmqv-m45h-q2hp
Sandbox Breakout / Arbitrary Code Execution in localeval
Quick fix
GHSA-mmqv-m45h-q2hp — localeval: upgrade to the fixed version with the command below.
npm install localeval@15.3.0Details
All versions of `localeval` are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context through `constructor.constructor`. This may allow attackers to execute arbitrary code in the system. Evaluating the payload ``` constructor.constructor("return process.env")() ```
returns the contents of `process.env`.
## Recommendation
No fix is currently available. Consider using an alternative package until a fix is made available.
Are you affected?
Enter the version of the package you're using.