vm2 is vulnerable to Prototype Pollution
100
Critical Risk
Write traps on bridged objects can reach host intrinsic prototypes in a way that mutates objects the host runtime relies on. Guest-controlled writes become prototype pollution that crosses the sandbox boundary into host behavior. That breaks isolation assumptions about what guest mutations can affect. The fix blocks those write paths from polluting host intrinsics.
You are affected if you are using a version that falls within the vulnerable range.
vm2 is vulnerable to Prototype Pollution in versions 3.9.6 - 3.10.5.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant