vm2 is vulnerable to Information Disclosure
100
Critical Risk
vm2 exposes the host Buffer object to sandboxed code, and small allocations through Buffer.allocUnsafe(), Buffer.from(), and Buffer.concat() draw from a memory pool shared with the host realm. By allocating from this shared pool, sandboxed code reads sensitive host memory that passes through those functions. It can also write into those buffers, corrupting host data. The fix isolates the sandbox from the shared Buffer pool.
You are affected if you are using a version that falls within the vulnerable range.
vm2 is vulnerable to Information Disclosure in versions 0.0.1 - 3.11.6.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant