VDB
Sign up
HIGH7.3

GHSA-x9hc-rw35-f44h

Sandbox Breakout / Arbitrary Code Execution in static-eval

Quick fix

GHSA-x9hc-rw35-f44h — static-eval: upgrade to the fixed version with the command below.

npm install static-eval@2.0.2

Details

Versions of `static-eval`prior to 2.0.2 pass untrusted user input directly to the global function constructor, resulting in an arbitrary code execution vulnerability when user input is parsed via the package.

## Proof of concept ``` var evaluate = require('static-eval'); var parse = require('esprima').parse;

var src = process.argv[2]; var payload = '(function({x}){return x.constructor})({x:"".sub})("console.log(process.env)")()' var ast = parse(payload).body[0].expression; console.log(evaluate(ast, {x:1})); ```

## Recommendation

Upgrade to version 2.0.2 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/static-eval
Introduced in: 0Fixed in: 2.0.2
Fixnpm install static-eval@2.0.2

References