From 36a8e911e6f58d0b87816fae0443c6ce8f5ea45a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=E0=A4=95=E0=A4=BE=E0=A4=B0=E0=A4=A4=E0=A5=8B=E0=A4=AB?= =?UTF-8?q?=E0=A5=8D=E0=A4=AB=E0=A5=87=E0=A4=B2=E0=A4=B8=E0=A5=8D=E0=A4=95?= =?UTF-8?q?=E0=A5=8D=E0=A4=B0=E0=A4=BF=E0=A4=AA=E0=A5=8D=E0=A4=9F=E2=84=A2?= Date: Wed, 6 Sep 2023 16:11:39 +0200 Subject: [PATCH] fix(Code Node): Disable WASM to address CVE-2023-37903 (#7122) [GH Advisory](https://github.com/advisories/GHSA-g644-9gfx-q4q4) --- packages/nodes-base/nodes/Code/JavaScriptSandbox.ts | 1 + 1 file changed, 1 insertion(+) diff --git a/packages/nodes-base/nodes/Code/JavaScriptSandbox.ts b/packages/nodes-base/nodes/Code/JavaScriptSandbox.ts index e15a37b73a..1b1da7f58d 100644 --- a/packages/nodes-base/nodes/Code/JavaScriptSandbox.ts +++ b/packages/nodes-base/nodes/Code/JavaScriptSandbox.ts @@ -42,6 +42,7 @@ export class JavaScriptSandbox extends Sandbox { console: 'redirect', sandbox: context, require: vmResolver, + wasm: false, }); this.vm.on('console.log', (...args: unknown[]) => this.emit('output', ...args));