{"id":"GHSA-4vmm-mhcq-4x9j","summary":"Sandbox Bypass Leading to Arbitrary Code Execution in constantinople","details":"Versions of `constantinople` prior to 3.1.1 are vulnerable to a sandbox bypass which can lead to arbitrary code execution.\n\n\n## Recommendation\n\nUpdate to version 3.1.1 or later.","modified":"2021-08-16T16:06:38Z","published":"2019-06-14T16:15:14Z","database_specific":{"cwe_ids":[],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2019-06-14T16:14:40Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/pugjs/constantinople/commit/01d409c0d081dfd65223e6b7767c244156d35f7f"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1577703"},{"type":"WEB","url":"https://snyk.io/vuln/npm:constantinople:20180421"},{"type":"WEB","url":"https://www.npmjs.com/advisories/568"}],"affected":[{"package":{"name":"constantinople","ecosystem":"npm","purl":"pkg:npm/constantinople"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-4vmm-mhcq-4x9j/GHSA-4vmm-mhcq-4x9j.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N"}]}