All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main application. Exported methods are stored in the application.remote object.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-JS-JAILED-2391490 | third party advisory exploit |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2441254 | third party advisory exploit |