Description
Versions of realms-shim prior to 1.2.1 are vulnerable to a Sandbox Breakout. The Realms evaluation function has an option to apply Babel-like transformations to the source code before it reaches the evaluator. One portion of this transform pipeline exposed a primal-Realm object to the rewriting function.
Recommendation
Update the realms-shim package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.2.1
- Patched version(s): 1.2.1
References
Related Issues
- Sandbox Breakout in realms-shim - realms-shim - Vulnerability
- Prototype Pollution in realms-shim - realms-shim - CVE-2021-23543
- Prototype Pollution in realms-shim - CVE-2021-23594
- Sandbox Breakout / Arbitrary Code Execution in localeval - Vulnerability
You might also like:
- Tags:
- npm
- realms-shim
Anything's wrong? Let us know Last updated on January 09, 2023


