vm2 is vulnerable to Protection Mechanism Failure
53
Medium Risk
The code transformer’s fast path can be bypassed using with, internal state naming, and certain unicode-escaped identifier shapes. That exposes a privileged internal state name to guest-transformed code. Attackers use that exposure as a pivot into broader sandbox weaknesses. The transformer and identifier handling are hardened so internal state cannot be reached through these syntax tricks.
You are affected if you are using a version that falls within the vulnerable range.
vm2 is vulnerable to Protection Mechanism Failure in versions 0.0.1 - 3.10.5.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant