mafintosh / append-tree

Model a tree structure on top off an append-only log.
MIT License
54 stars 13 forks source link

Sandbox Breakout / Arbitrary Code Execution (brfs) #11

Closed millette closed 6 years ago

millette commented 6 years ago

dat-node is affected by https://nodesecurity.io/advisories/548

brfs needs a patch https://github.com/browserify/brfs/pull/83 after static-eval (and static-module) were patched.

millette commented 6 years ago

IPFS solved it by removing the dependency.

mafintosh commented 6 years ago

fixed in latest