vm2 is vulnerable to Sandbox Escape
100
Critical Risk
The default builtin loader exposes the tls module through a read-only bridge that blocks property assignment but still permits calls to tls.setDefaultCACertificates(), which mutates the process-wide default certificate authority list. By chaining the tls and url builtins, sandboxed code builds a host-realm array of certificate data that passes the native type check. It then replaces the certificate authorities trusted by later host HTTPS clients, enabling credential theft and traffic tampering. The fix blocks the sandbox from mutating the host default trust store.
You are affected if you are using a version that falls within the vulnerable range and you expose the tls and url builtins to the sandbox.
vm2 is vulnerable to Sandbox Escape in versions 3.11.3 - 3.11.6.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant