Executive brief
safer-eval is a Node.js library that executes arbitrary JavaScript code within a restricted sandbox environment to prevent malicious operations. An attacker can bypass the sandbox restrictions and achieve arbitrary code execution by exploiting the Object.constructor property, potentially allowing them to execute unintended code or access the host system.
Technical details
The vulnerability is a sandbox breakout in safer-eval caused by improper restriction of the Object.constructor property. An attacker can use Object.constructor to escape the sandbox and execute arbitrary code on the host system. The vulnerability affects all versions prior to 1.3.2, where the fix explicitly disallows Object.constructor usage by prepending Object.constructor = function () {}; to the evaluated code. No special authentication or network access is required—exploitation only requires the ability to pass malicious code to the safer-eval library for evaluation.
Affected products
- commenthol safer-eval before 1.3.2
Timeline
- 2019-06-05: patched: Fix committed (Object.constructor restriction added)