Description
SandboxJS is a JavaScript sandboxing library. Prior to 0.8.29, as Map is in SAFE_PROTOYPES, it's prototype can be obtained via Map.prototype. By overwriting Map.prototype.has the sandbox can be escaped. This vulnerability is fixed in 0.8.29.
Problem types
CWE-94: Improper Control of Generation of Code ('Code Injection')
Product status
References
github.com/...dboxJS/security/advisories/GHSA-66h4-qj4x-38xp
github.com/...dboxJS/security/advisories/GHSA-66h4-qj4x-38xp
github.com/...ommit/67cb186c41c78c51464f70405504e8ef0a6e43c3