vm2 is vulnerable to Remote Code Execution
98
Critical Risk
Bridge code that restores saved state could end up invoking user-defined Array.prototype accessors during batch neutralization work. A sandbox-installed setter on indexed Array.prototype entries can run attacker code at a sensitive time and pivot to host execution. The failure is accidental sandbox callback execution from bridge-internal containers. The fix avoids that path by using Reflect.defineProperty style operations that do not trigger those prototype setters in the same way.
You are affected if you are using a version that falls within the vulnerable range.
vm2 is vulnerable to Remote Code Execution in versions 0.0.1 - 3.11.1.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant