vm2 is vulnerable to Protection Mechanism Failure
87
High Risk
Sandbox code can reach the host Symbol.for registry and bypass write-trap checks on symbol-keyed properties. That leaks host symbols into the sandbox and enables prototype and capability attacks leading to host code execution. Affected builds run untrusted code in VM or NodeVM without the symbol hardening. The fix tightens symbol handling and write-trap coverage in the bridge layer.
You are affected if you are using a version that falls within the vulnerable range.
vm2 is vulnerable to Protection Mechanism Failure in versions 3.0.0 - 3.11.3.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant