Vulnerabilities/

Sandbox Breakout in realms-shim

Severity:
High

Description

Versions of realms-shim prior to 1.2.1 are vulnerable to a Sandbox Breakout. The Realms evaluation function has an option to apply Babel-like transformations to the source code before it reaches the evaluator. One portion of this transform pipeline exposed a primal-Realm object to the rewriting function.

Recommendation

Update the realms-shim package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
realms-shim
Anything's wrong? Let us know Last updated on January 09, 2023