vm2 is vulnerable to Improper Access Control
99
Critical Risk
Negative builtin denials written with the node: prefix are not enforced because the sandbox strips the prefix before loading builtins while the denial list matches only the canonical name. A denial such as -node:child_process therefore never matches. Sandboxed code requires the canonical child_process module and reaches command-execution APIs that were meant to be blocked. The fix normalizes builtin names so prefixed denials are enforced.
You are affected if you are using a version that falls within the vulnerable range and you rely on a negative builtin denylist entry written with the node: prefix.
vm2 is vulnerable to Improper Access Control in versions 0.0.1 - 3.11.6.
Upgrade the vm2 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant