
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (GHSA-9pcf-h8q9-63f6) affects the safe-eval npm package, which was discovered to contain a critical Sandbox Breakout vulnerability leading to Remote Code Execution. The issue was published on September 3, 2020, and affects all versions of the package (>=0.0.0). This high-severity security flaw was last updated on January 9, 2023, and notably, no patched versions are available (GitHub Advisory).
The vulnerability allows attackers to escape the sandbox environment and execute arbitrary code by chaining a function's callee and caller constructors. The technical exploit involves manipulating object properties and utilizing JavaScript's argument handling mechanisms. A proof-of-concept payload demonstrates how attackers can access the global scope and execute system commands through the Node.js child_process module (GitHub Advisory).
The vulnerability enables attackers to break out of the intended sandbox environment and execute arbitrary code on the affected system. This effectively negates the primary security feature of the safe-eval package, potentially allowing attackers to run any system commands with the same privileges as the Node.js process (GitHub Advisory).
The vulnerability is readily exploitable using a payload that chains function callee and caller constructors. A proof-of-concept exploit has been publicly documented that demonstrates how to execute system commands, such as 'pwd', through the vulnerability (GitHub Advisory).
No fix is currently available for this vulnerability. The recommended mitigation strategy is to discontinue the use of the safe-eval package and switch to alternative packages that provide similar functionality with proper security measures (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."