vm2 is vulnerable to Remote Code Execution
98
Critical Risk
Guest code can influence inspection paths that rebuild host-side behavior from leaked representations. Attackers chain that to regain dangerous constructors and execute code on the host. The issue is a sandbox breakout through util.inspect-style plumbing rather than a normal guest API. The release hardens inspection-related bridging so those reconstructor gadgets are eliminated.
You are affected if you are using a version that falls within the vulnerable range.
vm2 is vulnerable to Remote Code Execution in versions 0.0.1 - 3.10.5.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant