GHSA-jp99-5h8w-gmxc
UNKNOWNAll versions of @zhaoyao91/eval-in-vm are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context through this.constructor.constructor . This may allow attackers to execute arbitrary code in the system. Evaluating the payload this.constructor.constructor('return process.env')() prints the contents of process.env.
- Affected
- >=0.0.0
- Fixed in
- not stated
- Published
- 2020-09-04
- Source
- osv