Executive brief
The npm sandbox library is a code sandboxing module designed to safely execute untrusted JavaScript code. A flaw in input sanitization allows attackers to bypass sandbox restrictions using constructor manipulation, enabling arbitrary code execution on the host system. This eliminates the primary security boundary intended by the module.
Technical details
The vulnerability is a sandbox escape due to insufficient input sanitization affecting all versions through 0.8.2. Attackers can leverage constructor chains and Function constructors to access restricted contexts (this.process.mainModule) and load arbitrary modules, achieving remote code execution. No authentication or special preconditions are required—an attacker simply needs to pass malicious code to the sandbox.run() method. The vendor has not released a patch; users are advised to discontinue use of the library and select an alternative sandboxing solution.
Affected products
- npm sandbox through 0.8.2
Timeline
- 2020-09-02: disclosed
- 2020-09-02: advisory