asvd / jailed

execute untrusted code with custom permissions
MIT License
1.01k stars 69 forks source link

Sandbox Escape Bug in jailed with Node.js #64

Open seongil-wi opened 1 year ago

seongil-wi commented 1 year ago

application.disconnect();



Sandbox can be escaped by calling `propertyIsEnumerable.call` function.
Also, we can execute arbitrary shell code using process module.