Junglewise Threat Intelligence

CVE-2021-23771: notevil sandbox escape via prototype pollution

CVE-2021-23771 · Severity: low · CVSS 3.1 · Published 2022-03-18

Technologies: notevil (npm). Vendors: npm.

Executive brief

notevil is a JavaScript library designed to safely evaluate arbitrary code in a restricted sandbox environment. This vulnerability allows attackers to break out of the sandbox and pollute object prototypes, potentially leading to code execution or data manipulation in applications that use this library.

Technical details

The vulnerability is a sandbox escape leading to prototype pollution (CWE-1321). The package fails to properly restrict access to the main JavaScript context, allowing an attacker to add or modify an object's prototype and escape the sandbox restrictions. This vulnerability resulted from an incomplete fix to a prior sandbox escape issue (SNYK-JS-NOTEVIL-608878). No network or authentication is required; an attacker can exploit this by providing untrusted code to be evaluated by the library. The package has been deprecated and is no longer maintained.

Affected products

  • notevil notevil all versions up to 1.3.3
  • argencoders argencoders-notevil all versions up to 2.5.0

Timeline

  • 2022-03-18: disclosed: GHSA-8g4m-cjm2-96wq published
  • 2021-12-28: other: notevil repository archived; package marked as no longer maintained

References

Related threats