Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade @boxlite-ai/boxlite to version 0.9.0 or higher.
@boxlite-ai/boxlite is a BoxLite - Embeddable micro-VM runtime for secure, isolated code execution
Affected versions of this package are vulnerable to Improper Isolation or Compartmentalization in the mounting of host directories in read-only mode into VM. An attacker can gain unauthorized write access to the host filesystem by remounting a shared directory as read-write from within the guest environment.