QID 983176
QID 983176: Nodejs (npm) Security Update for safe-eval (GHSA-ww6v-677g-p656)
Affected versions of `safe-eval` are vulnerable to a sandbox escape. By accessing object constructors, un-sanitized user input can access the entire standard library and effectively break out of the sandbox.
## Proof of Concept:
This code accesses the process object and calls `.exit()`
```
var safeEval = require('safe-eval');
safeEval("this.constructor.constructor('return process')().exit()");
```
## Recommendation
Update to version 0.4.0 or later
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-ww6v-677g-p656 for updates pertaining to this vulnerability.
Vendor References
- GHSA-ww6v-677g-p656 -
github.com/advisories/GHSA-ww6v-677g-p656
CVEs related to QID 983176
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-ww6v-677g-p656 | safe-eval |
|