Description
Versions of realms-shim prior to 1.2.0 are vulnerable to a Sandbox Breakout. Reflect.construct can be used on the sandboxed Function constructor to reach the prototypes of the primal Realm, which may allow an attacker to escape the sandbox and execute arbitrary code.
Recommendation
Update the realms-shim package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.2.0
- Patched version(s): 1.2.0
References
Related Issues
- Sandbox Breakout in realms-shim - Vulnerability
- Prototype Pollution in realms-shim - realms-shim - CVE-2021-23543
- Prototype Pollution in realms-shim - CVE-2021-23594
- Sandbox Breakout / Arbitrary Code Execution in localeval - Vulnerability
You might also like:
- Tags:
- npm
- realms-shim
Anything's wrong? Let us know Last updated on January 09, 2023


