Executive brief
value-censorship is a JavaScript library designed to filter or redact sensitive values from data. All versions contain a flaw that allows attackers to escape its sandbox restrictions and execute arbitrary code on the system running the application. An attacker who can control input to the library could gain full system access and compromise the integrity and confidentiality of the affected application and its data.
Technical details
The vulnerability is a sandbox escape caused by insufficient validation of async function constructors within the value-censorship package. The library fails to properly restrict the Function constructor or similar code generation mechanisms, allowing attackers to construct and execute arbitrary code outside the intended sandbox constraints. An attacker can exploit this by supplying specially crafted input that leverages async function constructor syntax to execute arbitrary JavaScript. No authentication or special privileges are required; any application using the library to process untrusted data is at risk. No patch has been released; the advisory recommends switching to an alternative package.
Affected products
- npm value-censorship all versions
Timeline
- 2020-09-02: disclosed