Skip to content

Commit 5313594

Browse files
committed
test(security): cover nested Function callback bypass
Add safe-eval regressions for smuggling Function through native array callbacks reached via nested property access.
1 parent 3eace0d commit 5313594

1 file changed

Lines changed: 25 additions & 0 deletions

File tree

‎test/test.safe-eval.js‎

Lines changed: 25 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -328,6 +328,31 @@ checkBuiltInVMAndNodeVM(function (vmType, setBuiltInState) {
328328
}, "Function constructor is disabled");
329329
});
330330

331+
for (const generatedBody of [
332+
'return 42',
333+
"globalThis.TEST_NESTED_FUNCTION_RCE = 'RCE'"
334+
]) {
335+
it('nested property access cannot smuggle Function through native callbacks', () => {
336+
// The nested-property branch can expose Object as the
337+
// filter value; keep this path guarded against indirect
338+
// Function invocation by native array methods.
339+
// @ts-expect-error VM testing
340+
// eslint-disable-next-line unicorn/no-global-object-property-assignment -- Exploit test
341+
globalThis.TEST_NESTED_FUNCTION_RCE = 'not exploited';
342+
const path =
343+
`$[?(@.constructor[([ @.getPrototypeOf(@).constructor, 0 ].reduce(["${generatedBody}"].map).pop()())])]`;
344+
345+
assert.throws(() => {
346+
jsonpath({path, json: {x: {}}});
347+
}, 'Function constructor is disabled');
348+
assert.equal(
349+
// @ts-expect-error VM testing
350+
globalThis.TEST_NESTED_FUNCTION_RCE,
351+
'not exploited'
352+
);
353+
});
354+
}
355+
331356
it("10.4.1 RCE via call/apply/bind", () => {
332357
// @ts-expect-error VM testing
333358
// eslint-disable-next-line unicorn/no-global-object-property-assignment -- Exploit test

0 commit comments

Comments
 (0)