vm2 is vulnerable to Information Disclosure
53
Medium Risk
Process-wide observability builtins diagnostics_channel, async_hooks, and perf_hooks are not blocked when hosts allow them through require.builtin. Sandboxed code can subscribe to host HTTP diagnostic channels or read async resources and performance marks from the host application. That leaks authorization headers, session tokens, and request context across the vm2 boundary. The fix treats these modules as dangerous builtins.
You are affected if you are using a version that falls within the vulnerable range.
vm2 is vulnerable to Information Disclosure in versions 3.0.0 - 3.11.3.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant