Closed frederikprijck closed 1 year ago
Semgrep found 1 ssc-1286f396-f1d3-46c6-9e68-74429d10c3c4
finding:
Risk: vm2 versions before 3.9.15 are vulnerable to Improper Control Of Dynamically-Managed Code Resources due to improper control of dynamically-managed code resources related to Error.prepareStackTrace in unhandled async errors. A threat actor can bypass the sandbox protections to gain remote code execution rights on the host running the sandbox.
Fix: Upgrade this library to at least version 3.9.15 at node-auth0/yarn.lock:5494.
Reference(s): https://github.com/advisories/GHSA-7jxr-cg7f-gpgv, CVE-2023-29017
Created by ssc-1286f396-f1d3-46c6-9e68-74429d10c3c4.
Changes
Adds a very basic playground application to test the SDK manually when needed.
Checklist