Company
Date Published
Author
Idan Digmi
Word count
853
Language
English
Hacker News points
None

Summary

Snyk and CISPA collaborated on security research, identifying vulnerabilities in JavaScript and NodeJS environments, including sandbox escape gadgets and type-confusion issues in native NodeJS extensions. The collaboration resulted in the disclosure of several vulnerabilities, including CVE-2021-23771 and CVE-2022-21144, with Snyk's assistance in issuing CVEs and notifying maintainers. The partnership aims to make the open-source world safer for everyone, calling on other academic institutions to collaborate with Snyk to achieve this goal.