Vulnerabilities/

isolated-vm has vulnerable CachedDataOptions in API

Severity:
High

Description

If the untrusted v8 cached data is passed to the API through CachedDataOptions, the attackers can bypass the sandbox and run arbitrary code in the nodejs process. Version 4.3.7 changes the documentation to warn users that they should not accept cachedData payloads from a user.

Recommendation

Update the isolated-vm package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
isolated-vm
Anything's wrong? Let us know Last updated on August 24, 2023

This issue is available in SmartScanner Professional

See Pricing