Executive brief
safer-eval is a Node.js library that attempts to safely evaluate JavaScript code in an isolated sandbox. Versions before 1.3.2 contain a critical vulnerability that allows attackers to escape the sandbox and execute arbitrary code on the server by exploiting constructor properties. This can lead to complete system compromise if the application uses safer-eval to run untrusted code.
Technical details
The vulnerability is a sandbox escape (CWE-94) in safer-eval versions before 1.3.2, where an attacker can use JavaScript constructor properties to break out of the VM isolation and execute arbitrary code. The vulnerability requires the attacker to provide the code to be evaluated (via application usage of safer-eval), but does not require authentication or user interaction beyond that. The fix (version 1.3.2) disables the Object.constructor function within the sandbox context to prevent this technique. The attack is practical and demonstrated in public exploits.
Affected products
- safer-eval safer-eval before 1.3.2
Timeline
- 2019-10-15: disclosed: NVD published CVE-2019-10760
- 2019-10-17: advisory: GitHub advisory GHSA-hgch-jjmr-gp7w published
- 2019-10-16: patched: Fix committed to address Object.constructor sandbox escape