vm2 is vulnerable to Remote Code Execution
100
Critical Risk
Cross-realm bridging lets guest code extract host-only symbols from objects that should stay opaque. Those symbols become part of a gadget chain that reaches host execution. The failure is a trust-boundary bug between guest and host realms. The update restricts how symbols and realm edges interact across the bridge.
You are affected if you are using a version that falls within the vulnerable range.
vm2 is vulnerable to Remote Code Execution in versions 0.0.1 - 3.10.5.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant