GHSA-x9hc-rw35-f44h
Sandbox Breakout / Arbitrary Code Execution in static-eval
Quick fix
GHSA-x9hc-rw35-f44h — static-eval: upgrade to the fixed version with the command below.
npm install static-eval@2.0.2Details
Versions of `static-eval`prior to 2.0.2 pass untrusted user input directly to the global function constructor, resulting in an arbitrary code execution vulnerability when user input is parsed via the package.
## Proof of concept ``` var evaluate = require('static-eval'); var parse = require('esprima').parse;
var src = process.argv[2]; var payload = '(function({x}){return x.constructor})({x:"".sub})("console.log(process.env)")()' var ast = parse(payload).body[0].expression; console.log(evaluate(ast, {x:1})); ```
## Recommendation
Upgrade to version 2.0.2 or later.
Are you affected?
Enter the version of the package you're using.