Description
All versions of localeval are vulnerable to Sandbox Escape leading to Remote Code Execution. The package fails to restrict access to the main context through constructor.constructor. This may allow attackers to execute arbitrary code in the system. Evaluating the payload
returns the contents of process.env.
Recommendation
Update the localeval package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0, < 15.3.0
- Patched version(s): 15.3.0
References
Related Issues
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-876r-hj45-fw7g - Vulnerability
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-hgch-jjmr-gp7w - CVE-2019-10760
- Sandbox Breakout / Arbitrary Code Execution in safer-eval - safer-eval - GHSA-r3x4-wr4h-pw33 - CVE-2019-10759
- Sandbox Bypass Leading to Arbitrary Code Execution in constantinople - Vulnerability
You might also like:
- Tags:
- npm
- localeval
Anything's wrong? Let us know Last updated on January 16, 2026


