Intel

AIKIDO-2024-10136

postman-sandbox is vulnerable to Sandbox Escape

Sandbox Escape Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jun 21, 2024

50

Medium Risk

This Affects:

JSpostman-sandbox
0.0.0 - 4.1.5
Fixed in 5.0.0
Are you affected? Scan for Free

TL;DR

Affected versions of postman-sandbox are vulnerable to a sandbox escape, as access to the Module object is not adequately protected.

Who does this affect?

You are affected if you use a vulnerable version of postman-sandbox and (directly or indirectly) run untrusted scripts within the sandbox.

Background info

postman-sandbox is vulnerable to Sandbox Escape in versions 0.0.0 - 4.1.5.

How to fix this

Upgrade postman-sandbox to a patch version.