vm2 is vulnerable to Denial of Service
86
High Risk
When host code returns a promise across the sandbox bridge and the sandbox does not attach a rejection handler, the rejection is left unhandled on the host side. An unhandled promise rejection propagates to the host process and terminates it, and the earlier unhandled-rejection hardening does not cover this path. Sandboxed code triggers this to crash the embedding host process. The fix marks host promises as handled at the apply boundary so a rejection can no longer terminate the host.
You are affected if you are using a version that falls within the vulnerable range and your host code exposes functions that return promises to the sandbox.
vm2 is vulnerable to Denial of Service in versions 3.10.0 - 3.11.7.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.