javascript-sandbox-escape

1 article
sort: new top best
clear filter
0 8/10

A server-side template injection vulnerability in Handlebars template engine was discovered in the Shopify Return Magic app's email workflow feature, allowing remote code execution through prototype pollution and Object.prototype manipulation to bypass sandbox restrictions and execute arbitrary Node.js code.

Handlebars Shopify Return Magic HackerOne H1-514 Synack TrendMicro Matias
mahmoudsec.blogspot.com · devanshbatham/Awesome-Bugbounty-Writeups · 19 hours ago · details