vm2 is vulnerable to Information Disclosure
21
Low Risk
The sandbox stack-trace formatter appends frames with lines[lines.length] = value, invoking sandbox Array.prototype setters during bridge-internal work. That violates Defense Invariant #11 and lets untrusted code observe each formatted frame line. Today the captured value is a string, but the pattern matches prior species-based escapes. The fix uses prototype-bypassing property writes like other hardened bridge sites.
You are affected if you are using a version that falls within the vulnerable range.
vm2 is vulnerable to Information Disclosure in versions 3.0.0 - 3.11.3.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant