CVE-2022-23923

HIGH

jailed - Sandbox Bypass via Exported alert() Method

Title source: llm
STIX 2.1

Description

All versions of package jailed are vulnerable to Sandbox Bypass via an exported alert() method which can access the main application. Exported methods are stored in the application.remote object.

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-JAILED-2391490
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-2441254

Scores

CVSS v3 8.6
EPSS 0.0015
EPSS Percentile 35.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Details

Status published
Products (2)
jailed_project/jailed
npm/jailed 0npm
Published May 01, 2022
Tracked Since Feb 18, 2026