Executive brief
SES is a JavaScript sandbox library that confines guest code running inside isolated Compartments. A vulnerability in its import filtering allows guest code to bypass sandbox restrictions using the spread operator combined with dynamic import (e.g., `{...import('module')}`), enabling attackers to exfiltrate sensitive data or execute arbitrary code from the host environment depending on the deployment context.
Technical details
SES uses a regular expression pattern to block dynamic import expressions and prevent guest code from accessing the host's module system. The original pattern `(^|[^.])\\bimport(\\s*(?:\\(|/[/*]))` failed to detect the spread operator (`...`) syntax, allowing guest code to bypass the filter using constructs like `{...import('module')}`. An attacker with no initial endowments can access the host's dynamic import capability through this vector. On the web, exploitation enables arbitrary HTTP requests and potential code execution (unless blocked by Content-Security-Policy). In Node.js environments, this provides a direct path to arbitrary code execution via data URL imports. The fix adds the spread operator to the regex pattern: `(^|[^.]|\\.\\.\\.)\\bimport(\\s*(?:\\(|/[/*]))`. Patches are available for all affected 0.x version trains (0.13.5, 0.14.5, 0.15.24, 0.16.1, 0.17.1, 0.18.7 and later).
Affected products
- Endo SES >=0.13.0 <0.13.5, >=0.14.0 <0.14.5, >=0.15.0 <0.15.24, >=0.16.0 <0.16.1, 0.17.0, >=0.18.0 <0.18.7
Timeline
- 2023-08-09: disclosed
- 2023-08-09: patched