Vulnerability in the Python package Js2Py, downloaded over a million times a month

A vulnerability (CVE-2024-28397) has been identified in the Python package Js2Py, which was downloaded 1.2 million times last month. This vulnerability allows bypassing the sandbox isolation and executing code on the system when processing specially crafted JavaScript data. It can be exploited to attack programs that use Js2Py for executing JavaScript code. A fix is currently available only as a patch. A prototype exploit has been prepared to test the attack vector.

The Js2Py package implements a JavaScript interpreter and compiler, allowing JavaScript code to be executed in an isolated virtual machine or translated into a representation in Python. The project is entirely written in Python and does not use external JavaScript engines. In practice, the library is used in various web indexers, downloading systems, and website analyzers that support processing of content generated by JavaScript code.

Among the applications affected by the vulnerability are Lightnovel Crawler (a utility for downloading books from online services and saving them in various formats for offline reading), cloudscraper (which automatically bypasses bot protection pages used in Cloudflare CDN), and pyLoad (a download manager that supports processing pages generated by JavaScript). When processing specially crafted JavaScript content in these applications, an attacker can execute arbitrary code at the system level.

The vulnerability exists in the implementation of a global variable within js2py, allowing access to a Python object from JavaScript code executed in the isolated environment, despite the call to js2py.disable_pyimport() to disable the import of Python objects. To execute arbitrary code on the system, an attacker can exploit this vulnerability to gain access to the Popen object from the Python subprocess module. Notably, the change to address the vulnerability was submitted to the Js2Py project on March 1, but it has not yet been accepted after three and a half months.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster