Executive brief
jailed is a JavaScript library for executing untrusted code in a sandboxed environment. A vulnerability allows attackers to bypass the sandbox by exploiting an exported alert() method that can access the main application's context, potentially exposing sensitive data or executing unintended code with elevated privileges.
Technical details
The jailed library implements a sandbox for executing untrusted JavaScript code, but all versions up to 0.3.1 fail to properly isolate exported methods. The vulnerability exists because exported methods are stored in the application.remote object without adequate privilege separation. An attacker can invoke the exported alert() method, which retains access to the main application's context, allowing sandbox escape. This is a privilege boundary violation requiring only network access with no user interaction needed. Exploitation allows attackers to read sensitive data (confidentiality impact), modify application behavior (integrity impact), and potentially disrupt service (availability impact).
Affected products
- asvd jailed 0 through 0.3.1
Timeline
- 2022-05-03: disclosed
- 2022-05-01: advisory